[ubuntu/mantic-proposed] curl 8.2.1-1ubuntu1 (Accepted)

Gianfranco Costamagna locutusofborg at debian.org
Sat Aug 5 14:09:23 UTC 2023


curl (8.2.1-1ubuntu1) mantic; urgency=low

  * Merge from Debian unstable. Remaining changes:
    - Don't build-depend on python3-impacket on i386 so we can drop it
      (and its dependencies) from the i386 partial port.  It's only used for
      the tests, which do not block the build in any case.

curl (8.2.1-1) unstable; urgency=medium

  [ Samuel Henrique ]
  * New upstream version 8.2.1

  [ Sergio Durigan Junior ]
  * d/p/{90_gnutls,99_nss}.patch:
    Update GNUTls/NSS patches to unbreak tests/http/clients
  * Drop unnecessary patches.
    d/p/CVE-2023-27533.patch
    d/p/CVE-2023-27534.patch
    d/p/CVE-2023-27535.patch
    d/p/CVE-2023-27536.patch
    d/p/CVE-2023-27537.patch
    d/p/CVE-2023-27538.patch
    d/p/CVE-2023-28319.patch
    d/p/CVE-2023-28320-1.patch
    d/p/CVE-2023-28320.patch
    d/p/CVE-2023-28321.patch
    d/p/CVE-2023-28322.patch
    d/p/CVE-2023-32001.patch
    d/p/Use-OpenLDAP-specific-functionality.patch
    d/p/fix-unix-domain-socket.patch

curl (7.88.1-11) unstable; urgency=medium

  [ Carlos Henrique Lima Melara ]
  * Fix CVE-2023-32001: TOCTOU race condition in Curl_fopen():
    - Done by d/p/CVE-2023-32001.patch (Closes: #1041812).

  [ John Scott ]
  * LDAP backend: correct the usage of OpenLDAP-specific functionality being
    disabled with an upstream patch (Closes: #1041964)
    This corrects the improper fetching of binary attributes.
  * debian/tests: add a DEP-8 test that getting binary LDAP attributes works now

Date: Sat, 05 Aug 2023 16:06:26 +0200
Changed-By: Gianfranco Costamagna <locutusofborg at debian.org>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/curl/8.2.1-1ubuntu1
-------------- next part --------------
Format: 1.8
Date: Sat, 05 Aug 2023 16:06:26 +0200
Source: curl
Built-For-Profiles: noudeb
Architecture: source
Version: 8.2.1-1ubuntu1
Distribution: mantic
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Gianfranco Costamagna <locutusofborg at debian.org>
Closes: 1041812 1041964
Changes:
 curl (8.2.1-1ubuntu1) mantic; urgency=low
 .
   * Merge from Debian unstable. Remaining changes:
     - Don't build-depend on python3-impacket on i386 so we can drop it
       (and its dependencies) from the i386 partial port.  It's only used for
       the tests, which do not block the build in any case.
 .
 curl (8.2.1-1) unstable; urgency=medium
 .
   [ Samuel Henrique ]
   * New upstream version 8.2.1
 .
   [ Sergio Durigan Junior ]
   * d/p/{90_gnutls,99_nss}.patch:
     Update GNUTls/NSS patches to unbreak tests/http/clients
   * Drop unnecessary patches.
     d/p/CVE-2023-27533.patch
     d/p/CVE-2023-27534.patch
     d/p/CVE-2023-27535.patch
     d/p/CVE-2023-27536.patch
     d/p/CVE-2023-27537.patch
     d/p/CVE-2023-27538.patch
     d/p/CVE-2023-28319.patch
     d/p/CVE-2023-28320-1.patch
     d/p/CVE-2023-28320.patch
     d/p/CVE-2023-28321.patch
     d/p/CVE-2023-28322.patch
     d/p/CVE-2023-32001.patch
     d/p/Use-OpenLDAP-specific-functionality.patch
     d/p/fix-unix-domain-socket.patch
 .
 curl (7.88.1-11) unstable; urgency=medium
 .
   [ Carlos Henrique Lima Melara ]
   * Fix CVE-2023-32001: TOCTOU race condition in Curl_fopen():
     - Done by d/p/CVE-2023-32001.patch (Closes: #1041812).
 .
   [ John Scott ]
   * LDAP backend: correct the usage of OpenLDAP-specific functionality being
     disabled with an upstream patch (Closes: #1041964)
     This corrects the improper fetching of binary attributes.
   * debian/tests: add a DEP-8 test that getting binary LDAP attributes works now
Checksums-Sha1:
 9570fd40b6479e707b591ce2065c3466f29c631a 3321 curl_8.2.1-1ubuntu1.dsc
 fb9fd702a322e395abd7f1f6b9ff8841aa54ccb9 4394020 curl_8.2.1.orig.tar.gz
 c514d2b0325460d762255c11b5fa204ae230ac47 488 curl_8.2.1.orig.tar.gz.asc
 a0a1e8021da2dd7bd2fe687b3874ef9b863a0f13 46956 curl_8.2.1-1ubuntu1.debian.tar.xz
 79cadc93be45803aa677ee2b1463ff68699510e9 9618 curl_8.2.1-1ubuntu1_source.buildinfo
Checksums-Sha256:
 6a8c462d0ecf82fbb5ec6c46ae58e6cbe9a06ab4ff0bc563f5db68941f3125e2 3321 curl_8.2.1-1ubuntu1.dsc
 f98bdb06c0f52bdd19e63c4a77b5eb19b243bcbbd0f5b002b9f3cba7295a3a42 4394020 curl_8.2.1.orig.tar.gz
 b3d8b2576891427ca038a83581372ebc18f648952f6693db5cb3a89f5bf7f4d3 488 curl_8.2.1.orig.tar.gz.asc
 902f3a64cd8b931d79555a4f4d5f45d6e87b914601b70d6bd8c07740981523ee 46956 curl_8.2.1-1ubuntu1.debian.tar.xz
 8778fe927c261e0632afd4a9fb04bcaae9041ae570bc30246dc505e611d97ca9 9618 curl_8.2.1-1ubuntu1_source.buildinfo
Files:
 0e806b2ab8e2b240921690353ecc2cab 3321 web optional curl_8.2.1-1ubuntu1.dsc
 b25588a43556068be05e1624e0e74d41 4394020 web optional curl_8.2.1.orig.tar.gz
 a2c737ab908e2b338922a954501d865f 488 web optional curl_8.2.1.orig.tar.gz.asc
 349b877c0ebf97db244afde61695e501 46956 web optional curl_8.2.1-1ubuntu1.debian.tar.xz
 a3a7648cfceb16ced6ae64faaf4a27aa 9618 web optional curl_8.2.1-1ubuntu1_source.buildinfo
Original-Maintainer: Alessandro Ghedini <ghedo at debian.org>


More information about the mantic-changes mailing list