[ubuntu/natty-security] curl 7.21.3-1ubuntu1.2 (Accepted)

Steve Beattie sbeattie at ubuntu.com
Thu Jun 23 23:03:27 UTC 2011


curl (7.21.3-1ubuntu1.2) natty-security; urgency=low

  * SECURITY UPDATE: libcurl unconditional credential delegation during
    GSSAPI authentication vulnerability.
    - debian/patches/0001-Curl_input_negotiate-do-not-delegate-credentials.patch:
      do not delegate credentials when doing GSSAPI authentication
    - CVE-2011-2192

Date: Tue, 21 Jun 2011 09:36:52 -0700
Changed-By: Steve Beattie <sbeattie at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/natty/+source/curl/7.21.3-1ubuntu1.2
-------------- next part --------------
Format: 1.8
Date: Tue, 21 Jun 2011 09:36:52 -0700
Source: curl
Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg
Architecture: source
Version: 7.21.3-1ubuntu1.2
Distribution: natty-security
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Steve Beattie <sbeattie at ubuntu.com>
Description: 
 curl       - Get a file from an HTTP, HTTPS or FTP server
 libcurl3   - Multi-protocol file transfer library (OpenSSL)
 libcurl3-dbg - libcurl compiled with debug symbols
 libcurl3-gnutls - Multi-protocol file transfer library (GnuTLS)
 libcurl3-nss - Multi-protocol file transfer library (NSS)
 libcurl4-gnutls-dev - Development files and documentation for libcurl (GnuTLS)
 libcurl4-nss-dev - Development files and documentation for libcurl (NSS)
 libcurl4-openssl-dev - Development files and documentation for libcurl (OpenSSL)
Changes: 
 curl (7.21.3-1ubuntu1.2) natty-security; urgency=low
 .
   * SECURITY UPDATE: libcurl unconditional credential delegation during
     GSSAPI authentication vulnerability.
     - debian/patches/0001-Curl_input_negotiate-do-not-delegate-credentials.patch:
       do not delegate credentials when doing GSSAPI authentication
     - CVE-2011-2192
Checksums-Sha1: 
 4429d703bf1d7a53df2ae3fd1bac5bc1ef8d6ece 2266 curl_7.21.3-1ubuntu1.2.dsc
 7ccb53b1681cd44146231394a3a510a44899672a 97257 curl_7.21.3-1ubuntu1.2.debian.tar.gz
Checksums-Sha256: 
 748fa4e7cf2ea1a5bc552b75a21a0614be53018293d33594c2b19686c8cd8f8d 2266 curl_7.21.3-1ubuntu1.2.dsc
 1e9a493aeb61afff6584ed4ceab2a5da968a342195ef79cefc2f8f2ddd1015a4 97257 curl_7.21.3-1ubuntu1.2.debian.tar.gz
Files: 
 2f0c0b95f567f20641f973ca82f80718 2266 web optional curl_7.21.3-1ubuntu1.2.dsc
 56602af85e08ff77bd48cf4e91ce64be 97257 web optional curl_7.21.3-1ubuntu1.2.debian.tar.gz
Original-Maintainer: Ramakrishnan Muthukrishnan <rkrishnan at debian.org>


More information about the Natty-changes mailing list