-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 02 Apr 2023 20:34:17 +0100 Source: curl Binary: curl curl-dbgsym libcurl3-gnutls libcurl3-gnutls-dbgsym libcurl3-nss libcurl3-nss-dbgsym libcurl4 libcurl4-dbgsym libcurl4-gnutls-dev libcurl4-nss-dev libcurl4-openssl-dev Architecture: mipsel Version: 7.74.0-1.3+deb11u8 Distribution: bullseye Urgency: medium Maintainer: mips64el Build Daemon (mipsel-osuosl-01) Changed-By: Samuel Henrique Description: curl - command line tool for transferring data with URL syntax libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.74.0-1.3+deb11u8) bullseye; urgency=medium . * Backport upstream patches to fix 5 CVEs: - CVE-2023-27533: TELNET option IAC injection - CVE-2023-27534: SFTP path ~ resolving discrepancy - CVE-2023-27535: FTP too eager connection reuse - CVE-2023-27536: GSS delegation too eager connection re-use - CVE-2023-27538: SSH connection too eager reuse still * d/p/add_Curl_timestrcmp.patch: New patch to backport Curl_timestrcmp(), required for CVE-2023-27535. Checksums-Sha1: 28b76e2653b116e1e77d4a20da25c203179f2676 140884 curl-dbgsym_7.74.0-1.3+deb11u8_mipsel.deb f7f5bf95119cdbbb250040013d5340e9a9a54dfd 12313 curl_7.74.0-1.3+deb11u8_mipsel-buildd.buildinfo 4713f324c264839d506075f6a5c68c60fd66f406 266624 curl_7.74.0-1.3+deb11u8_mipsel.deb a429426eee518e54baffc4db0a3444909156bf20 813476 libcurl3-gnutls-dbgsym_7.74.0-1.3+deb11u8_mipsel.deb 7026b2da074ddb7fe422aa6190ddb85a36a110d9 325592 libcurl3-gnutls_7.74.0-1.3+deb11u8_mipsel.deb e8b076d5f90b2d136857aaf9d6535be60cb91ced 855400 libcurl3-nss-dbgsym_7.74.0-1.3+deb11u8_mipsel.deb f2d22961cba7e83c6fbfe4ccd5e0417944bf4cdf 333088 libcurl3-nss_7.74.0-1.3+deb11u8_mipsel.deb 035e30ad3d4b383395f09a57f156c395ec2bc271 830156 libcurl4-dbgsym_7.74.0-1.3+deb11u8_mipsel.deb 147acc83c5ebce8d8ea00a38adc9c55447c527a3 451384 libcurl4-gnutls-dev_7.74.0-1.3+deb11u8_mipsel.deb e1a9a449b07fb9491aa7774ec9846cb1d852928b 460648 libcurl4-nss-dev_7.74.0-1.3+deb11u8_mipsel.deb 8b04fa70432901711d0c6441d5b0d499b55d75b4 456176 libcurl4-openssl-dev_7.74.0-1.3+deb11u8_mipsel.deb 6953c044631df4ddc208a3bdaf017058f87a2255 328960 libcurl4_7.74.0-1.3+deb11u8_mipsel.deb Checksums-Sha256: 738bb3da2436600cbce516399598ae9f81988152329a402b16e5c2193adc270e 140884 curl-dbgsym_7.74.0-1.3+deb11u8_mipsel.deb c5db523034ef0534791179474f067a66b61e2f433f15915595372dda03387974 12313 curl_7.74.0-1.3+deb11u8_mipsel-buildd.buildinfo 513fb9eda6eb9189745030f45c1907db781b681c849aeb7bd6dfaa37eba1bbd0 266624 curl_7.74.0-1.3+deb11u8_mipsel.deb 8ea70456d0eacc6ba3702b6211f91e59228f6b58cfdde097eab6ebfd52803898 813476 libcurl3-gnutls-dbgsym_7.74.0-1.3+deb11u8_mipsel.deb cee8b721b1f542d8fa1628d0dd537a1c5fbc0f28e42489143fb6fb0c237d24fc 325592 libcurl3-gnutls_7.74.0-1.3+deb11u8_mipsel.deb 98317882cbefdf44690dc3612690f5e23d38b273d0b33fb2303054256fbe7d6e 855400 libcurl3-nss-dbgsym_7.74.0-1.3+deb11u8_mipsel.deb 082ac6058367b2adde50c6d26907474d05172d7a1dfcaa62f74947f5bb9d8adb 333088 libcurl3-nss_7.74.0-1.3+deb11u8_mipsel.deb a8622061af27280a1e429591facabc5ec2ad6b0cb7194284205dd8bbef912728 830156 libcurl4-dbgsym_7.74.0-1.3+deb11u8_mipsel.deb 878acbf2faeee86c54833c5e0b9a35705816a08c9a3db69f87a919246532088d 451384 libcurl4-gnutls-dev_7.74.0-1.3+deb11u8_mipsel.deb 6c2d135f1c2631cf244cc3a4efa78f12b6865304d5019819a87fbd2dda64e026 460648 libcurl4-nss-dev_7.74.0-1.3+deb11u8_mipsel.deb 598480b1bf7d1113be5ca98b3bbc850013614dbd423c8834eb57c0ddd57a6a99 456176 libcurl4-openssl-dev_7.74.0-1.3+deb11u8_mipsel.deb b7b39198a54c197af345d38c15db413cc7fe2801a08e741a1d22a7e1ccf542a8 328960 libcurl4_7.74.0-1.3+deb11u8_mipsel.deb Files: 8bd9d800dd177155271a011a95e62188 140884 debug optional curl-dbgsym_7.74.0-1.3+deb11u8_mipsel.deb 88ac7e2eb5aaed4648533dc0544e8144 12313 web optional curl_7.74.0-1.3+deb11u8_mipsel-buildd.buildinfo ba85c4d390a131ce9a0366af61a492c2 266624 web optional curl_7.74.0-1.3+deb11u8_mipsel.deb f9db2b2aa097fd1155bfc17251a79bb1 813476 debug optional libcurl3-gnutls-dbgsym_7.74.0-1.3+deb11u8_mipsel.deb f34133fc22b0d5c2d872f76423e3f9c8 325592 libs optional libcurl3-gnutls_7.74.0-1.3+deb11u8_mipsel.deb 560e9a6190db9c3b6f70e1c2728f437b 855400 debug optional libcurl3-nss-dbgsym_7.74.0-1.3+deb11u8_mipsel.deb 0358bef2b52659122cd9b84a20ce00c0 333088 libs optional libcurl3-nss_7.74.0-1.3+deb11u8_mipsel.deb 90ac6c92342e56b9c5127e8c4f04a990 830156 debug optional libcurl4-dbgsym_7.74.0-1.3+deb11u8_mipsel.deb 4e48642d3082aee55aa2505a29e77b34 451384 libdevel optional libcurl4-gnutls-dev_7.74.0-1.3+deb11u8_mipsel.deb 1b97081ea8c0f36121864dd1ecf002f1 460648 libdevel optional libcurl4-nss-dev_7.74.0-1.3+deb11u8_mipsel.deb 0078f2df6af34fec87b0a533237c036b 456176 libdevel optional libcurl4-openssl-dev_7.74.0-1.3+deb11u8_mipsel.deb a39c6767c2a53de48e99755b5ba969ea 328960 libs optional libcurl4_7.74.0-1.3+deb11u8_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7gvl9o8phoQDAS3o7Lbsjpk9n6sFAmSeen4ACgkQ7Lbsjpk9 n6t9uQ/+MEjP6lfIEyFXbRpyvYH0dnt9Rd8aASQWyuoCi02LEakoKtVB0gT5znSi j2367UPFLIc/vb8GWpWcMq9AAIF5SCTASBUzJUP12k7prQUdcJYIWiP5IGL6asaw OmbjYofN5PgbRCb01QbqS2/Ok4JIw7VidijQm1tjIF9Jw7bI2ztf+47NAnfnMuNp T6ylncYLfkwLez3tb5KhbyKGVXSbZffuCCyt14pxNy/81pF48wAn59mJ4/YFXFAt lnqtOi3yyiQS33es4hnjX3pOOZ2lh0w9SpMUSSgz2JPU+iqaL4tiEIzYZ6IXcTrA ewxoQMNrkWMCUzU+UnVYsjlTpynD1vc/kdpDdURsPEbi8+l1hT76Y+fgW3JCtXI2 EH/8nixyeHk052aQ5tS2tR8JbRrpqitK7/2dlCjSnNLzAdrF9EmBYS4utwQHXOY/ hTc3r6FgzFysZemGnMusv5L2K2ve9VoalQB3FL2L/no6O9Z8cLqKBHP1jucU71KU JMDJ9L5CrU7Sd4Q87hfTbEXgLJUS3a9aFPwUZK9T8xIWR+mW3AQ6q6tPZ+ynHzLw gc+gvNiHXIqaDEVkb7qtkMHelRPuuBpQb7NWgVaN6jkut/fJvCY5ezrlF4QLd1+1 CP9Q3RFYCB9aiSzLYnJHO8/L1A6k5bAgxo84VgfTYcs2OJy1UeM= =/RN6 -----END PGP SIGNATURE-----