-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Sat, 16 Nov 2013 13:04:23 +0100 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg Architecture: armel Version: 7.26.0-1+wheezy5 Distribution: wheezy-security Urgency: high Maintainer: armel Build Daemon (alwyn) Changed-By: Alessandro Ghedini Description: curl - command line tool for transferring data with URL syntax libcurl3 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours) libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.26.0-1+wheezy5) stable-security; urgency=high . * Fix OpenSSL checking of a certificate CN or SAN name field when the digital signature verification is turned off as per CVE-2013-4545 http://curl.haxx.se/docs/adv_20131115.html * Set urgency=high accordingly Checksums-Sha1: 53e0ed6a3785ffbeca9763500c3fc1b2c1e117a4 268444 curl_7.26.0-1+wheezy5_armel.deb 06c95a5e4d8307b5efc552308d08156b98002902 316316 libcurl3_7.26.0-1+wheezy5_armel.deb 53f565fa2eca2a6ce8032fce6f3223c98c19dc5a 307710 libcurl3-gnutls_7.26.0-1+wheezy5_armel.deb ea88751042fb8fac763b4094d9e3e91f8c642bcc 314204 libcurl3-nss_7.26.0-1+wheezy5_armel.deb bdf25a477b017985897c325b48c196bacab01fd5 1227562 libcurl4-openssl-dev_7.26.0-1+wheezy5_armel.deb 77f1b1d37f9800e0db8af6c31fc8efdfc95846e3 1222752 libcurl4-gnutls-dev_7.26.0-1+wheezy5_armel.deb ee1d0d4de41205720b559915cbe36fcf0b990940 1226672 libcurl4-nss-dev_7.26.0-1+wheezy5_armel.deb 1fde85739d841626f4200c9b8b7f47c8b3b0bb58 2810984 libcurl3-dbg_7.26.0-1+wheezy5_armel.deb Checksums-Sha256: c576d018c71959ee8bf35e32eaf3a1d129f287e17a7a0d474cd648c8c6a73b43 268444 curl_7.26.0-1+wheezy5_armel.deb ddca6885e799c74e6c54956688c3dcf258ced4309f04dfddd155729710d17255 316316 libcurl3_7.26.0-1+wheezy5_armel.deb 24c2b118b49f4b61d5f3348ee2b9a853f5c8da1fe237027d5948a0b1b5ad07de 307710 libcurl3-gnutls_7.26.0-1+wheezy5_armel.deb 7797431b940c72cf878ed50f468bc9a81676079f8705fef50f784bfb75234db8 314204 libcurl3-nss_7.26.0-1+wheezy5_armel.deb cfe4a1faf1941c1c6edfc57d1801235eeb19d3ad316bf897e05dd4f85fd3549e 1227562 libcurl4-openssl-dev_7.26.0-1+wheezy5_armel.deb 1037823d3b7774edbbd5d8eb246176567e975615b20053cca2309bd056a1f32b 1222752 libcurl4-gnutls-dev_7.26.0-1+wheezy5_armel.deb 11daf903c6c336ed893c47edc8dea4808d3f5c2b0d751e6556612019747a72f3 1226672 libcurl4-nss-dev_7.26.0-1+wheezy5_armel.deb f0728b8c8d7ba2829918c24cc653e4754d8d8bb87e8e8217b2810cc374cc422e 2810984 libcurl3-dbg_7.26.0-1+wheezy5_armel.deb Files: 2319fe01832a0a430a426a458fb779e5 268444 web optional curl_7.26.0-1+wheezy5_armel.deb e1b0be99251ec4893d99d28986386799 316316 libs optional libcurl3_7.26.0-1+wheezy5_armel.deb f33adf5938685a50f9aed77a37db2c3c 307710 libs optional libcurl3-gnutls_7.26.0-1+wheezy5_armel.deb 5ab95bd8255afd64c659b713906f6d0b 314204 libs optional libcurl3-nss_7.26.0-1+wheezy5_armel.deb 4ea095bdbf657cc78d809396190d8c31 1227562 libdevel optional libcurl4-openssl-dev_7.26.0-1+wheezy5_armel.deb 737ca98a82b59118016501a6e971273d 1222752 libdevel optional libcurl4-gnutls-dev_7.26.0-1+wheezy5_armel.deb 06bf98f491a4dbe94d81393b581daa7d 1226672 libdevel optional libcurl4-nss-dev_7.26.0-1+wheezy5_armel.deb fe467f9c4de9e8f5c00125f5d0a81863 2810984 debug extra libcurl3-dbg_7.26.0-1+wheezy5_armel.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQIcBAEBCAAGBQJSiN/zAAoJEHV1HA9d+sCq9Z8QAI82xipvYSl2VlUoNFeCZ13L hSph1vX6Luw4rX7n/eStXQ6zSlojphS6L85IfMwtpX2WV+pQJZKdGBnld0fEZck0 JNk2yTNB3F2g7VGjloDCBqlJakrylUrWi7RINGE7aghvL+Ei8gJ+zYw8nyegRnOu 9mL4Wbj3SoHS3nd9Jyu+eNCQCYeuUmJ/oJIzkn6DnevPwYV+AliosI6UL1c1Ot1G phjgZnLksLglpKnKBRnU1jn8uFEw/dLusB0/o3O+gRGdXKIDoFpAk4u3LMbh3e1s hKOwiobdMimJGmXq+Mq7qtiDiobcWzBhcLTAoIQzCaxnfOlAErEE6pwQULiSEcnP i3olMjIsTbbilVizIG+zehDwBsbFdTA1GlPZkDq+R0E62Hs0d/w+pZuoiLG24Zac sFtQni6nFXdJG3sqCjEyx4+fgVFmPuat55uZW/0gCJItwEKoxjQ60bpKRO1u4Wph RvUcmi+SWVe8bzg4wCo5H/xs6Ihww5R1STTJhggBtTHOyml5LILEppsweiPkcVmB oAbDHCKqFSuUgC7M6uBAJMMi+dUP+k6QLqFHr/NN5ooiWkeHgtkO4vK8N+U8h5/0 MyLq7ZS69RTQpU2206fxVH/wgTiuXX1sZ4Agnhuou54SSNGYx3rZtrEcUqdGDAFW 1/1u3Itctd/9XtFWCg5y =mUJm -----END PGP SIGNATURE-----