-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 02 Apr 2024 20:02:10 -0300 Source: curl Binary: curl curl-dbgsym libcurl3-gnutls libcurl3-gnutls-dbgsym libcurl3-nss libcurl3-nss-dbgsym libcurl4 libcurl4-dbgsym libcurl4-gnutls-dev libcurl4-nss-dev libcurl4-openssl-dev Architecture: ppc64el Version: 7.88.1-10+deb12u6 Distribution: bookworm Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-conova-02) Changed-By: Guilherme Puida Moreira Description: curl - command line tool for transferring data with URL syntax libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Closes: 1053643 Changes: curl (7.88.1-10+deb12u6) bookworm; urgency=medium . * Team upload. . [ Sergio Durigan Junior ] * d/p/openldap-create-ldap-URLs-correctly-for-IPv6-addresses.patch: (Closes: #1053643) . [ Guilherme Puida Moreira ] * Add patches to fix CVE-2024-2004 and CVE-2024-2398. - CVE-2024-2004: When a protocol selection parameter disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. - CVE-2024-2398: When an application tells libcurl it wants to allow HTTP/2 server push and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push and leaks the memory allocated for the previously allocated headers. * d/p/openldap-create-ldap-URLs-correctly-for-IPv6-addresses.patch: Refresh patch. Checksums-Sha1: add30ef85befbae6d70d0c840c163975adc564ce 163572 curl-dbgsym_7.88.1-10+deb12u6_ppc64el.deb b6479f91cda8abd62a699adc6c2d504acdddc316 12985 curl_7.88.1-10+deb12u6_ppc64el-buildd.buildinfo fd23ebee042969d85ddd5c926e59e60c5e06ec6a 315320 curl_7.88.1-10+deb12u6_ppc64el.deb 9eac98c84c363142829eff3b1d5d30fc894ed77e 1047528 libcurl3-gnutls-dbgsym_7.88.1-10+deb12u6_ppc64el.deb 63ddceebcc86d56cfad28db2b9ed1b1299a6728b 405612 libcurl3-gnutls_7.88.1-10+deb12u6_ppc64el.deb 51993bea23071f77c0dcbb60dd898c768fc77c42 1091476 libcurl3-nss-dbgsym_7.88.1-10+deb12u6_ppc64el.deb ca950a29de52a02fa136d901dd0defad39ea07e3 416240 libcurl3-nss_7.88.1-10+deb12u6_ppc64el.deb a1e57e51232e58fdc97f18e3b9cc6cc70b27b311 1076480 libcurl4-dbgsym_7.88.1-10+deb12u6_ppc64el.deb 09698452c92d506b0e8b4bd7862d3950942d68c6 517112 libcurl4-gnutls-dev_7.88.1-10+deb12u6_ppc64el.deb a44fa4753c9230a8da6b9d75914508aa9efad352 528128 libcurl4-nss-dev_7.88.1-10+deb12u6_ppc64el.deb 6f2f646990608edced18b95778487823f41fa337 521808 libcurl4-openssl-dev_7.88.1-10+deb12u6_ppc64el.deb fa34394a0979442df4ea607b609ee8d35ea4940c 410312 libcurl4_7.88.1-10+deb12u6_ppc64el.deb Checksums-Sha256: 528fec9ae2f0d4b9c4854df7c442f34b03d401d6ecc224e01a0fcc71c88b67ec 163572 curl-dbgsym_7.88.1-10+deb12u6_ppc64el.deb 837a25bb8d975f7c37ace7d6b9bf25a12adfab16d78841448b1280989104b8d7 12985 curl_7.88.1-10+deb12u6_ppc64el-buildd.buildinfo df48d7ff2b166d0600b38d6c6c2f17313a5f69f6258355112897fc603789b652 315320 curl_7.88.1-10+deb12u6_ppc64el.deb 299c2240356c231472cd663b91f96ade071347873560cd3cc9fa70742be63407 1047528 libcurl3-gnutls-dbgsym_7.88.1-10+deb12u6_ppc64el.deb 487c10466f303a501eb0577f91f4fd41c4b0430fb3e0b6414a12b844b17802b1 405612 libcurl3-gnutls_7.88.1-10+deb12u6_ppc64el.deb c58dcf4aa39e071615f109ac2b1a6e75700f1c883a4862b76bb5deca9f3bae2c 1091476 libcurl3-nss-dbgsym_7.88.1-10+deb12u6_ppc64el.deb bb467ab41a246243018bc300ae7ab9957a4da3108a12bf0bf32b6696c8f725d0 416240 libcurl3-nss_7.88.1-10+deb12u6_ppc64el.deb 130f905c170eb545812d9c022120ad44c58092675cce65c49c138e278bee905d 1076480 libcurl4-dbgsym_7.88.1-10+deb12u6_ppc64el.deb a9b3ddfd12bcb581835573d208b5d8806443de2482c84d961c948f77f73ef324 517112 libcurl4-gnutls-dev_7.88.1-10+deb12u6_ppc64el.deb c87f1b1c7914020b81bd9bf308af4e0242ff9bd17aae13434639d49988488dd7 528128 libcurl4-nss-dev_7.88.1-10+deb12u6_ppc64el.deb 16441ee2e5e9b1daa84e466996a83738f18e1b9deaf5555660125ea600520cef 521808 libcurl4-openssl-dev_7.88.1-10+deb12u6_ppc64el.deb 57f7582fd7f3f0d8b2d5c2872134688c4ff56334bfbc11aae370bf4db9d3290b 410312 libcurl4_7.88.1-10+deb12u6_ppc64el.deb Files: 030cd0188c60e51f9a26686e2eac3901 163572 debug optional curl-dbgsym_7.88.1-10+deb12u6_ppc64el.deb 0dcb9dc86146867b2f4f397cce460c49 12985 web optional curl_7.88.1-10+deb12u6_ppc64el-buildd.buildinfo cea4ef26a858efd6d11b461afe7f24e7 315320 web optional curl_7.88.1-10+deb12u6_ppc64el.deb 01eac3f127d31c64d9e4f4c64ac48f08 1047528 debug optional libcurl3-gnutls-dbgsym_7.88.1-10+deb12u6_ppc64el.deb 7d056de3dfe44385da81ab6d4e35a7c9 405612 libs optional libcurl3-gnutls_7.88.1-10+deb12u6_ppc64el.deb 41800abb84a6c77019bb4cf5a1df4fef 1091476 debug optional libcurl3-nss-dbgsym_7.88.1-10+deb12u6_ppc64el.deb 602399a1ff563f86d8f06b7eb5dedd93 416240 libs optional libcurl3-nss_7.88.1-10+deb12u6_ppc64el.deb 97b648047d0abd07eeed8e5df9408267 1076480 debug optional libcurl4-dbgsym_7.88.1-10+deb12u6_ppc64el.deb 6619168537f16ad044e87b733f6fad4d 517112 libdevel optional libcurl4-gnutls-dev_7.88.1-10+deb12u6_ppc64el.deb 7f423aea8cff4a36d29c3039d4e5a142 528128 libdevel optional libcurl4-nss-dev_7.88.1-10+deb12u6_ppc64el.deb 7bd26fc9fb88f86116023a1f51946016 521808 libdevel optional libcurl4-openssl-dev_7.88.1-10+deb12u6_ppc64el.deb 98fd8f8ac28ae77e78fc433fd1ac4a1b 410312 libs optional libcurl4_7.88.1-10+deb12u6_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmyxOicioak1AZZAyyPVDLEOGa2QFAmYVfNMACgkQyPVDLEOG a2TakBAAsaQ2BXCeMQFjxTxnfo2OZNmjby6EMu7s2YEHL09d7TdEiGYUi7Hw5i2c h8qLFRb8t5EFI5SLSis+2Z9/o6cEfaQhGzHoVH9IW3PcbWSBFeDYKPAakwLTQH56 jrQ8xf8PRVfVFIrNADwzRkeWc+MAPcEux93IHsMbmR6EMNmGyCcaBI2JiDC2B1Qc gzcdu7wgiNhDZQQEwxaCI3y2sHTFTGGWtSaOQV3KahtrlUfsIlzNyUt8rtSJyx9j +xiIdTkZ9a6e/E+wJ1LXUgn3tga4lDmMx4ypMuBP/9u7UYymdftqNkn2UdTo9t7U YKifg4rxu7DxHytHTvg56VyOgfs0mP+hRKndB3yshJSU1IDh51lsxzE/9OZc6WDr r2055NtOSi0qE75uvHzrPDQymdc6HeAP78JA4WLqdpYhzUyvuvkwdmV6g21FRfA5 D8fVYAGuOzB1TwCDqdiMs0fgQ2GzY/JeECGhsJcZjTHzQWzeVa6u48rbD13SZlgf JlPpPHUvW5PLc+pxmEUF3RA16NRa1eZiqYH5UDu4ELheGfdBMitfl0m8EmN6PkX+ Sm0RvV9cCBHXWXWOngaHmsExV2Hne6lXsh+JcpigYpYKI7DLhjDZ/PWM4MO3FulF Me0zc9nWhBTDILrhrRDSICBRE2e9Rk4HOJwNjxe3Z4drgJd9ixQ= =FWaI -----END PGP SIGNATURE-----