-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 24 Jan 2012 15:14:25 +0100 Source: curl Binary: curl libcurl3 libcurl3-gnutls libcurl4-openssl-dev libcurl4-gnutls-dev libcurl3-dbg Architecture: powerpc Version: 7.21.0-2.1+squeeze1 Distribution: squeeze-security Urgency: high Maintainer: powerpc Build Daemon (porpora) Changed-By: Alessandro Ghedini Description: curl - Get a file from an HTTP, HTTPS or FTP server libcurl3 - Multi-protocol file transfer library (OpenSSL) libcurl3-dbg - libcurl compiled with debug symbols libcurl3-gnutls - Multi-protocol file transfer library (GnuTLS) libcurl4-gnutls-dev - Development files and documentation for libcurl (GnuTLS) libcurl4-openssl-dev - Development files and documentation for libcurl (OpenSSL) Changes: curl (7.21.0-2.1+squeeze1) stable-security; urgency=high . * Non-maintainer upload * Fix URL sanitization vulnerability as per CVE-2012-0036 http://curl.haxx.se/docs/adv_20120124.html * Fix SSL CBC IV vulnerability as per CVE-2011-3389 http://curl.haxx.se/docs/adv_20120124B.html * Set urgency=high accordingly Checksums-Sha1: 19e923fbc44fbe8788758045cc9cb7faf3ba65b8 228908 curl_7.21.0-2.1+squeeze1_powerpc.deb f9b345f61b32ccea7f571343d160a339a7ea1fda 296012 libcurl3_7.21.0-2.1+squeeze1_powerpc.deb f74a1cc3715c1ab7ff99b045621cbeff1cb35c69 275540 libcurl3-gnutls_7.21.0-2.1+squeeze1_powerpc.deb a3a7a5c8c8126371c7d5a555a96862611a83a24b 1093704 libcurl4-openssl-dev_7.21.0-2.1+squeeze1_powerpc.deb 3fd4a4527d11a21e8b1d2c93f6b732697943f7d2 1069842 libcurl4-gnutls-dev_7.21.0-2.1+squeeze1_powerpc.deb a7fea3e1c2fd00463322aa7c779e51701e2188ad 117150 libcurl3-dbg_7.21.0-2.1+squeeze1_powerpc.deb Checksums-Sha256: b4b945c5f10ae67f6e33cadfc122e6118531f39763adbc4ceddd20e413f4db5f 228908 curl_7.21.0-2.1+squeeze1_powerpc.deb 959b54036e02a2812d5a75283214f0cfa5613fc5996a3965e7700c02f567a8b4 296012 libcurl3_7.21.0-2.1+squeeze1_powerpc.deb 0b42f53ba9b06ebb19d4c60b0118b1efcb88419454d65d80086d9e1aaad28a3e 275540 libcurl3-gnutls_7.21.0-2.1+squeeze1_powerpc.deb 913e8cbcaa7abf5014348005525d893ad08c030a01aa8fe9fea44422319b933b 1093704 libcurl4-openssl-dev_7.21.0-2.1+squeeze1_powerpc.deb d40ac3958a522c77321c73148d424d6291e3cb894c8d98ed8f22112f1b518e3d 1069842 libcurl4-gnutls-dev_7.21.0-2.1+squeeze1_powerpc.deb 9675e6688b4ab3a73e93894201c7dde549f060ad54b8a20ba903978bd2bf9227 117150 libcurl3-dbg_7.21.0-2.1+squeeze1_powerpc.deb Files: aca251c947f8a38397243e93d620dd6d 228908 web optional curl_7.21.0-2.1+squeeze1_powerpc.deb 65c587cc46cef683656cad7bb3a80796 296012 libs optional libcurl3_7.21.0-2.1+squeeze1_powerpc.deb 042c5bfad982abdfabc991fcfaae4eac 275540 libs optional libcurl3-gnutls_7.21.0-2.1+squeeze1_powerpc.deb dfd821e862e87a4be6dfed5209876df1 1093704 libdevel optional libcurl4-openssl-dev_7.21.0-2.1+squeeze1_powerpc.deb 83dfe59a83e3bf112554fb635b2f0493 1069842 libdevel optional libcurl4-gnutls-dev_7.21.0-2.1+squeeze1_powerpc.deb 31319cbe7a779bff78e68f250b7e6830 117150 debug extra libcurl3-dbg_7.21.0-2.1+squeeze1_powerpc.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBCAAGBQJPJUwwAAoJELzJGFiM510FycoP/jlVGqF3HCcOPtKVZMgGmnpg tRPmoV5b4qCvkH3jSXUemTGDqeiWgAXos+0Bvsu4ecDTMKEOVmV7M9fPCFQARUc3 79U85TNP76w/KY7l1nW6HPXaNpx7seqPH9Ql83TLjO/GJLquZco2nCsnuc4B9YBu 9pLg/NrI4wX6dx65BE2XcCxRfT34wNWRsw6nVih+IOKWrDT9ygE3eO6LgclL0Vq4 Lb/huEbU0CiAGa4V3deEITdIzCU29wRkJUNG7Wz+hgAtHKQe4XcHddpWhD2tXhl6 3C+DcBlkkM4qtQbJ/8HU+Hwk/AVV9zZH98faXsSCobL2Z68XjDeSLXNPJxx/Q1I7 FZzmLAdEvGvJzGUU0YajfjYz2396F0Y3wHrutWvBVGVpe58W78+fEvsXTVQlk4TV GEzM0rTMS6Qu8pweBk3dHuG7FDr38iGlo76VPNtpdwNTQWjXvN3GATYU/OvfLn2L iOPhXj1Hh6nV+Yph4JJdoc22cu6QarCpY+JyB7PFroIN1R+LHPT44+l/cRkhFoku gF4eZUZMabydfV8N3Ag7lc3eH2WNiADFfoH0VO/yaUBNTNwKch+kUO7u2SpFSYn8 PL/f10ini6DoCZVOC039Ee2EIZLXZcmt8wY3UrKo7GAskwdlPvfauVib7LP2Zp7K zO/NCXct3wk5YtPQSFtm =32Ya -----END PGP SIGNATURE-----