-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Sat, 16 Nov 2013 13:04:23 +0100 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl3-nss libcurl4-openssl-dev libcurl4-gnutls-dev libcurl4-nss-dev libcurl3-dbg Architecture: kfreebsd-amd64 Version: 7.26.0-1+wheezy5 Distribution: wheezy-security Urgency: high Maintainer: kfreebsd-amd64 Build Daemon (fayrfax) Changed-By: Alessandro Ghedini Description: curl - command line tool for transferring data with URL syntax libcurl3 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl3-dbg - debugging symbols for libcurl (OpenSSL, GnuTLS and NSS flavours) libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.26.0-1+wheezy5) stable-security; urgency=high . * Fix OpenSSL checking of a certificate CN or SAN name field when the digital signature verification is turned off as per CVE-2013-4545 http://curl.haxx.se/docs/adv_20131115.html * Set urgency=high accordingly Checksums-Sha1: d04d788594f0d14f1fbe144ede8cf1aa0f826c75 270040 curl_7.26.0-1+wheezy5_kfreebsd-amd64.deb 45e219ad0e8e039afed4cded42410f143b22c145 330918 libcurl3_7.26.0-1+wheezy5_kfreebsd-amd64.deb 5888b37dbe3e9174bbe329227441886af9bbf946 321574 libcurl3-gnutls_7.26.0-1+wheezy5_kfreebsd-amd64.deb 43907e092a0b6bb67cb91cdac132180b0664cd6b 328552 libcurl3-nss_7.26.0-1+wheezy5_kfreebsd-amd64.deb 781d9bee4f78dad57d7a70ede099ea175e04fc41 1246362 libcurl4-openssl-dev_7.26.0-1+wheezy5_kfreebsd-amd64.deb 204956636e0274add2d50e1f054eb42930dba180 1236254 libcurl4-gnutls-dev_7.26.0-1+wheezy5_kfreebsd-amd64.deb a4369c718eb5c45311193fe026ef849cdf15bad1 1243036 libcurl4-nss-dev_7.26.0-1+wheezy5_kfreebsd-amd64.deb 88620581786b6f1affbca3985861a98032aa59e1 3331958 libcurl3-dbg_7.26.0-1+wheezy5_kfreebsd-amd64.deb Checksums-Sha256: f7cf0d2507e9ccda3667699ce7ad59a428df6e9ad0754e3fea25178f866d70ec 270040 curl_7.26.0-1+wheezy5_kfreebsd-amd64.deb 548fb458914e709cfb68fe818f54295946b4a60a60fb424d46249d2a59cd758c 330918 libcurl3_7.26.0-1+wheezy5_kfreebsd-amd64.deb 58eca8a55dfe0c644e04286b682a4bb8e34af9b1304e5b22fb1dd841f57da5f5 321574 libcurl3-gnutls_7.26.0-1+wheezy5_kfreebsd-amd64.deb 2173ad279519ea2c0618b7d1e091eba87e68da0366826d531ecf032908b2ad4a 328552 libcurl3-nss_7.26.0-1+wheezy5_kfreebsd-amd64.deb 155bbf43cc3a87060ac44fbd803b2147977919a8d27ce6ef252091e6bd6554d0 1246362 libcurl4-openssl-dev_7.26.0-1+wheezy5_kfreebsd-amd64.deb 906aeb84eb22b47bb6aedb91dfc8af15ee707d655d8a731cb3d8a79da25e31c6 1236254 libcurl4-gnutls-dev_7.26.0-1+wheezy5_kfreebsd-amd64.deb 610b8234a3a8114098938bd85958059816579ca5a7c77a336359642f1531d432 1243036 libcurl4-nss-dev_7.26.0-1+wheezy5_kfreebsd-amd64.deb a1cb706337ca001f45c2cfa8242103abd46f3d2f9294d3ec265cbb397d1aec20 3331958 libcurl3-dbg_7.26.0-1+wheezy5_kfreebsd-amd64.deb Files: 673739c40ac5adfb1bd3426e270cf168 270040 web optional curl_7.26.0-1+wheezy5_kfreebsd-amd64.deb aa24cb6a3b6e8cb2c8c7db2e44508f77 330918 libs optional libcurl3_7.26.0-1+wheezy5_kfreebsd-amd64.deb 4ab99ab7fb6abe6cd7f0bbb9d24a20aa 321574 libs optional libcurl3-gnutls_7.26.0-1+wheezy5_kfreebsd-amd64.deb df786789e2437bb2788be8c0df3c1374 328552 libs optional libcurl3-nss_7.26.0-1+wheezy5_kfreebsd-amd64.deb b7297b09c5347ca9468ac9a2a8fedffb 1246362 libdevel optional libcurl4-openssl-dev_7.26.0-1+wheezy5_kfreebsd-amd64.deb 58d03f073b679ca6bf96a0127bf9d8ac 1236254 libdevel optional libcurl4-gnutls-dev_7.26.0-1+wheezy5_kfreebsd-amd64.deb 15de0a5757afce3a46774e2d98949080 1243036 libdevel optional libcurl4-nss-dev_7.26.0-1+wheezy5_kfreebsd-amd64.deb c331cb05f7780977b9de21fe720d423f 3331958 debug extra libcurl3-dbg_7.26.0-1+wheezy5_kfreebsd-amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/kFreeBSD) iQIcBAEBAgAGBQJSiMEmAAoJEDUVBmyiAQ1eYbgQAKTwcIUX4Evp+gGlPZiCZT7r VnBnHHkMGsfZg+B0o3HWJXLa7oBRy0w3t9coCWEFnGZredh51TTYQd4EHGfG7Z/y jZKtOI9kFY+Rj/+PXnhHDzBeQuDMH574Jzhc5vX+YGGdFxO5hD0K8KBsUbUsTeG6 5Rx87jiPEovP49d9iz7zx/x1/Rzu5QzPnPly5HmZ0ohIBh7LHHauRoGrmLRm+V17 Mptx6cwJk3Plzs1kQwzPSer5Eu8mISd/efhjiQ/zJTxMRnD9lKGXWhyVRMdAmNTh tJhVyZ1NEzIYxzW/x7Xx+jvezJtro+xuTwP+RUk+8CocINuWMiD1mVECvSBATWFx jXDv80qlhSgP/Yq1ydYijWTY0VI9PTpL9HKZCTlwQiwCAewWPS6OU/nG1/6AQju4 4xRDUcBclVURvNaHfWxbqxfoc6rf+YdXbh4c52LQIQLnVxNrouUchNT/5J7KwlJS PxzEjt6XqZmQSt4YX2263ZUeeRuoF47kzIrL5S0lJKn4Z6QU7pxojur3FD21dpA9 pnyDC/uVL8PWfPnm8AIywgFqluKbrPtBY7SmWNGnnfU6GQ40G5K59xW3SsK9qFBC 4+dSvc+KIuH9BKWkglMuiKK6C2j+EP8SItjkVmdoLSiD3RBEiJI5rrNP0BPjwhcX /gue7JzIegabi33nIO6i =hems -----END PGP SIGNATURE-----