-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 02 Apr 2024 20:02:10 -0300 Source: curl Binary: curl curl-dbgsym libcurl3-gnutls libcurl3-gnutls-dbgsym libcurl3-nss libcurl3-nss-dbgsym libcurl4 libcurl4-dbgsym libcurl4-gnutls-dev libcurl4-nss-dev libcurl4-openssl-dev Architecture: mipsel Version: 7.88.1-10+deb12u6 Distribution: bookworm Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Guilherme Puida Moreira Description: curl - command line tool for transferring data with URL syntax libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Closes: 1053643 Changes: curl (7.88.1-10+deb12u6) bookworm; urgency=medium . * Team upload. . [ Sergio Durigan Junior ] * d/p/openldap-create-ldap-URLs-correctly-for-IPv6-addresses.patch: (Closes: #1053643) . [ Guilherme Puida Moreira ] * Add patches to fix CVE-2024-2004 and CVE-2024-2398. - CVE-2024-2004: When a protocol selection parameter disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. - CVE-2024-2398: When an application tells libcurl it wants to allow HTTP/2 server push and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push and leaks the memory allocated for the previously allocated headers. * d/p/openldap-create-ldap-URLs-correctly-for-IPv6-addresses.patch: Refresh patch. Checksums-Sha1: fb4b4a310870dbd42a4ccc9bcd3ef44fc61ac069 162772 curl-dbgsym_7.88.1-10+deb12u6_mipsel.deb e850d60abf36e3c3172aa15ad5090d35e1462a51 12824 curl_7.88.1-10+deb12u6_mipsel-buildd.buildinfo 3954012e215aa1671631fc815a478289fff68166 311044 curl_7.88.1-10+deb12u6_mipsel.deb c21919518b24bc07401839efd0ccfb35b9d8e857 1034408 libcurl3-gnutls-dbgsym_7.88.1-10+deb12u6_mipsel.deb 6f08d478295dc0a59e45089afbda8b5a7e97dfd2 363428 libcurl3-gnutls_7.88.1-10+deb12u6_mipsel.deb 7878f4d5a6bd9013d309f627dc45f61116e198e9 1081164 libcurl3-nss-dbgsym_7.88.1-10+deb12u6_mipsel.deb fb273bdc93d7114aea8292412b778e46e9652f8c 371636 libcurl3-nss_7.88.1-10+deb12u6_mipsel.deb ad76a7df2b9a3f01a0694a08b0073ffb29650c14 1060824 libcurl4-dbgsym_7.88.1-10+deb12u6_mipsel.deb 81a79992c6bde96d6891f31a648c07ab9da7fc96 502096 libcurl4-gnutls-dev_7.88.1-10+deb12u6_mipsel.deb a415291968ce6591650797485af89299ed5d3690 511784 libcurl4-nss-dev_7.88.1-10+deb12u6_mipsel.deb fde060d457cddcb230a4cd11698bdd7842f8989c 508916 libcurl4-openssl-dev_7.88.1-10+deb12u6_mipsel.deb c53195c56b6ba497bbb4128ee195fdef140550d6 368676 libcurl4_7.88.1-10+deb12u6_mipsel.deb Checksums-Sha256: 032bf7c88422a8460664690da0569fd4c27228fd49917541e5009b12484fb3ee 162772 curl-dbgsym_7.88.1-10+deb12u6_mipsel.deb 99c035330c3ccbc11d2d22ce4cc3e4ca7ecf9ae33a7688f78367e87f044f58be 12824 curl_7.88.1-10+deb12u6_mipsel-buildd.buildinfo 6dc1cfc11146d7912b20689051f895106ed8c0b29b229b598b38619b9ccdc016 311044 curl_7.88.1-10+deb12u6_mipsel.deb 617ee33149ff5011eed584b13492c2cb7b61d1c59adbb528e0cedc005780bdac 1034408 libcurl3-gnutls-dbgsym_7.88.1-10+deb12u6_mipsel.deb 66b7e3996a34e79f7fc2829bf546a97b6462a8fd3ee7a53c7c2ad45b0b2464ea 363428 libcurl3-gnutls_7.88.1-10+deb12u6_mipsel.deb 82ef8c4cff0a66ae631a38b77c25556c39cd5a7268fe8ca0e5191c4a9cffa6b3 1081164 libcurl3-nss-dbgsym_7.88.1-10+deb12u6_mipsel.deb 5fe80acb3bb0a7fe34bd9feb79e9fa23929edcbe6060a6dd63228e7b18447fe2 371636 libcurl3-nss_7.88.1-10+deb12u6_mipsel.deb 67b3670f3b5a25d94a817d6c4b7445333e08aa57e6f2363e3e49085f7de414e6 1060824 libcurl4-dbgsym_7.88.1-10+deb12u6_mipsel.deb 71408e8a637449731906000a3d4ac409af355dee24571513edf7197654257a20 502096 libcurl4-gnutls-dev_7.88.1-10+deb12u6_mipsel.deb c3c64b1b25898ab0cf47f9e9dd6fc8f026436ef452226e86366303e5cc331039 511784 libcurl4-nss-dev_7.88.1-10+deb12u6_mipsel.deb c51dc3dee9cb8e84b251f9ff5da5d8dce8591af2a609b9e6aa5a06882f1db730 508916 libcurl4-openssl-dev_7.88.1-10+deb12u6_mipsel.deb 65b8fdfd08a64db1999355ba269ce1fd7a9adf58f11819013af270f86043eabd 368676 libcurl4_7.88.1-10+deb12u6_mipsel.deb Files: 3db9261f2b29133ae72f4b0b44957344 162772 debug optional curl-dbgsym_7.88.1-10+deb12u6_mipsel.deb 0f1eab9fd0c1f4db47dcba21caa0baf9 12824 web optional curl_7.88.1-10+deb12u6_mipsel-buildd.buildinfo b9a2b6728e42539cd4e6135897920d3d 311044 web optional curl_7.88.1-10+deb12u6_mipsel.deb 93dc7ca4d21c21fffca6582e5ae5f683 1034408 debug optional libcurl3-gnutls-dbgsym_7.88.1-10+deb12u6_mipsel.deb 81e36b4e77e23fda56695fb24fb2ce9c 363428 libs optional libcurl3-gnutls_7.88.1-10+deb12u6_mipsel.deb 2ca98cf59cada4e69876d0ae8914546c 1081164 debug optional libcurl3-nss-dbgsym_7.88.1-10+deb12u6_mipsel.deb a10fb464d87543c2fa4f42b530aded3c 371636 libs optional libcurl3-nss_7.88.1-10+deb12u6_mipsel.deb d8af17f1079bd1ea26468944a4c21354 1060824 debug optional libcurl4-dbgsym_7.88.1-10+deb12u6_mipsel.deb 896bea2e27528690af58b6e824cd3c7e 502096 libdevel optional libcurl4-gnutls-dev_7.88.1-10+deb12u6_mipsel.deb 608105239774866e41173bb0dd43e5a8 511784 libdevel optional libcurl4-nss-dev_7.88.1-10+deb12u6_mipsel.deb b1e563d2dfb3992557ef47169858c20c 508916 libdevel optional libcurl4-openssl-dev_7.88.1-10+deb12u6_mipsel.deb 5b1ba64026542df37b9c3f9a4595f3e5 368676 libs optional libcurl4_7.88.1-10+deb12u6_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEuQAPGkYIXAAfq7z1C2Vm2FYVKKAFAmYVggsACgkQC2Vm2FYV KKDv/g/+NdLnlii3LjwgCAsWHg3sXObln89uQ/CqaNp3jdc0P+afsl0DCK1ir+Gq 2uZeolBrNtgHJR9EQHZE4yOttD6r6peVhLTRE9+CzyA1poPXq4kAyJoTLZNT7uVd 5Ye1qhobbi0sW0568PVzOFqj/c4pCCfoCKylSrASoJ1lmqzabAe7uSXFkX/JN0BX +CTUCDM8ZNhHy8tpMVrJkn3JiCQ44gRYWm4SjcsCgc4aAMobbia7QjvbE8LFho3N xemto6pvIIE/UoGwPl9ZL4W7SAt/s9whHj1kJ1GrPnYWWroYMV60s5P+J84CYCR0 EGFLnfVPZnLLkx+CpxFcdKpJUbNwA2IDH+rky0s/TV/V7dn/yC+s5DLUqiVfVAcB UNSPetst9EtTm0kdPzva+26UkFQm4O+zFN1WctfEEi+B5bBNlw7KVnpUzBj9FOki SwogwUE7YX+zpws1ii5FR+Pj/To2eLymgXC6hiIdK+IhbXcrCNqTE4kz4AFX0Z3l Jx15/yFeihXz1w7FvIA8jw2nRBb0+CYFVrkP17bzVNBEEHdpFANpYKiT9KwdzkWC G3gprIqHkJjFfx4OvNFu4C8DgDZThi4JdFGrXpvAaf1Bgtdym2d3AHVa9Qh++YhJ NmT7/awSnvwHRbhDtj/8flEzvmyOFVr4frclH+zdQWH0ydN+nqY= =8bjg -----END PGP SIGNATURE-----