Format: 1.8 Date: Mon, 09 May 2022 08:34:24 -0400 Source: curl Binary: curl libcurl3-gnutls libcurl3-nss libcurl4 libcurl4-gnutls-dev libcurl4-nss-dev libcurl4-openssl-dev Built-For-Profiles: noudeb Architecture: riscv64 Version: 7.81.0-1ubuntu1.2 Distribution: jammy Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: curl - command line tool for transferring data with URL syntax libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.81.0-1ubuntu1.2) jammy-security; urgency=medium . * SECURITY UPDATE: percent-encoded path separator in URL host - debian/patches/CVE-2022-27780.patch: reject percent-decoding host name into separator bytes in lib/urlapi.c. - CVE-2022-27780 * SECURITY UPDATE: CERTINFO never-ending busy-loop - debian/patches/CVE-2022-27781.patch: return error if seemingly stuck in a cert loop in lib/vtls/nss.c. - CVE-2022-27781 * SECURITY UPDATE: TLS and SSH connection too eager reuse - debian/patches/CVE-2022-27782.patch: check more TLS details for connection reuse in lib/setopt.c, lib/url.c, lib/urldata.h, lib/vtls/gtls.c, lib/vtls/openssl.c, lib/vtls/nss.c, lib/vtls/vtls.c, lib/vssh/ssh.h. - CVE-2022-27782 Checksums-Sha1: 78251658760feb38ec9d1c72bccf252a697952a4 155288 curl-dbgsym_7.81.0-1ubuntu1.2_riscv64.ddeb 8894cd8a33e3685c7ca9a80f9742969624d8ba3e 12757 curl_7.81.0-1ubuntu1.2_riscv64.buildinfo 8150ffbcd178c7c2a5930c8473a626a46bbfecbb 188486 curl_7.81.0-1ubuntu1.2_riscv64.deb 0cce9a00828d8655c5209ea3963ef3f86f2675f7 919970 libcurl3-gnutls-dbgsym_7.81.0-1ubuntu1.2_riscv64.ddeb e2c63b6723c0409f6a31985934d48f7bf3ea9ce9 249744 libcurl3-gnutls_7.81.0-1ubuntu1.2_riscv64.deb a60649fe014abcd6b794173ee60af41c3d1d672f 962096 libcurl3-nss-dbgsym_7.81.0-1ubuntu1.2_riscv64.ddeb 6f5f9f5716b95f76bd3c800cda908af74bf507ef 259460 libcurl3-nss_7.81.0-1ubuntu1.2_riscv64.deb b81334f23e759a368be81947003c4d2904b0ced6 948742 libcurl4-dbgsym_7.81.0-1ubuntu1.2_riscv64.ddeb 589aff70cf09403f38595e198f351052df916e25 846082 libcurl4-gnutls-dev_7.81.0-1ubuntu1.2_riscv64.deb a0bbe8f366e7d5f7696ac19c6f8c67dbe3455a82 868078 libcurl4-nss-dev_7.81.0-1ubuntu1.2_riscv64.deb 35f7b1a69ffeeeb4c2a3b36c3494a88989e54e39 865232 libcurl4-openssl-dev_7.81.0-1ubuntu1.2_riscv64.deb 1af8d3f2cacbd4b0caaf3b99d15e6143bf55784f 256104 libcurl4_7.81.0-1ubuntu1.2_riscv64.deb Checksums-Sha256: 9cb5934b88906699529fbf1f81d0fd8d2602658ed9d18e882164555d2d662a09 155288 curl-dbgsym_7.81.0-1ubuntu1.2_riscv64.ddeb 0daa99e0721706ad7d92f1a2bf758652e78ce97fa9a93c2f2b15fc89d9b54eca 12757 curl_7.81.0-1ubuntu1.2_riscv64.buildinfo 070bc22c1b537fa7c4fdd3a3ab0d3aa1b088d414b8f155a41a17d03918a0a04c 188486 curl_7.81.0-1ubuntu1.2_riscv64.deb b07db58a466e2909ef0387fbf33db7299df4a04f2a29d6e729317c2960eac9fa 919970 libcurl3-gnutls-dbgsym_7.81.0-1ubuntu1.2_riscv64.ddeb af283a1e022e950683348c795306c010eaeac65a0e45e84eaf378f9fe5389adf 249744 libcurl3-gnutls_7.81.0-1ubuntu1.2_riscv64.deb 06c0ebacab5e50845dfaac89a8305e88216a41a7d12c03a28ded3082b44fc227 962096 libcurl3-nss-dbgsym_7.81.0-1ubuntu1.2_riscv64.ddeb 32e8bcf056e9169d492067d2c0ea673faf8478d2fae13141d3b6fdf6f6677200 259460 libcurl3-nss_7.81.0-1ubuntu1.2_riscv64.deb 390f961021be3b5a15819aa73d60ac0a6009ccebb07f17a68458f755588b6393 948742 libcurl4-dbgsym_7.81.0-1ubuntu1.2_riscv64.ddeb e0aed81932d7ea6e3ac71b5ac69ecb35726bbf20dccc3f696b253921ba53d158 846082 libcurl4-gnutls-dev_7.81.0-1ubuntu1.2_riscv64.deb bdd5bb2b465dd493e3f7cac761e77db38d0b27040f6c7f4713847185a3e119c1 868078 libcurl4-nss-dev_7.81.0-1ubuntu1.2_riscv64.deb 4c66da505c3dcbf4aa5a4fbb9d7ab9bd771cb5e0fdc4041f1d17be9a0343038f 865232 libcurl4-openssl-dev_7.81.0-1ubuntu1.2_riscv64.deb 7f819b99aef5bec0f576a4bd17db935e3a2fda9f879430ead5bb92d403a03206 256104 libcurl4_7.81.0-1ubuntu1.2_riscv64.deb Files: d1e1c1957018244478bd6db07472abb7 155288 debug optional curl-dbgsym_7.81.0-1ubuntu1.2_riscv64.ddeb 60744b03f21cd70c4baf980ce7351e9f 12757 web optional curl_7.81.0-1ubuntu1.2_riscv64.buildinfo e13d3fe0ed869f4273bbb1f9bde7bcd7 188486 web optional curl_7.81.0-1ubuntu1.2_riscv64.deb 75cb5664252e1b348719b9c7b000cbaf 919970 debug optional libcurl3-gnutls-dbgsym_7.81.0-1ubuntu1.2_riscv64.ddeb 32fee367b8faac0e5d3baa070b4c31fb 249744 libs optional libcurl3-gnutls_7.81.0-1ubuntu1.2_riscv64.deb 83aad52c4fe5b64a552bbde73eb47153 962096 debug optional libcurl3-nss-dbgsym_7.81.0-1ubuntu1.2_riscv64.ddeb bc726b11010b97aaea462ed9cafd9c2d 259460 libs optional libcurl3-nss_7.81.0-1ubuntu1.2_riscv64.deb 6bf7402652b535b3ecbfcf9782e4acf1 948742 debug optional libcurl4-dbgsym_7.81.0-1ubuntu1.2_riscv64.ddeb 8ed84e03fa4afff76ea903b7a1c0b3e8 846082 libdevel optional libcurl4-gnutls-dev_7.81.0-1ubuntu1.2_riscv64.deb cd7e08fccd0e45cee8c210a5f6ed1607 868078 libdevel optional libcurl4-nss-dev_7.81.0-1ubuntu1.2_riscv64.deb aa1c4a9b08b2b73e75273a19e8491d67 865232 libdevel optional libcurl4-openssl-dev_7.81.0-1ubuntu1.2_riscv64.deb 9937353a07f649a569b535ff2c4171d0 256104 libs optional libcurl4_7.81.0-1ubuntu1.2_riscv64.deb Original-Maintainer: Alessandro Ghedini