curl (7.88.1-10+deb12u6) bookworm; urgency=medium
authorGuilherme Puida Moreira <guilherme@puida.xyz>
Tue, 2 Apr 2024 23:02:10 +0000 (20:02 -0300)
committerGuilherme Puida Moreira <guilherme@puida.xyz>
Tue, 2 Apr 2024 23:02:10 +0000 (20:02 -0300)
commit0465df4b9f55876c0a4c4a44d1a262984ddd00f8
tree98c3c85c08c92699fa1c18244fbd481311e2f6c4
parent6f0dc41c18d1799ca7f24898807d967e97d75a9f
parentca454f44f9a10b94176f37030ed89b2381cadc43
curl (7.88.1-10+deb12u6) bookworm; urgency=medium

  * Team upload.

  [ Sergio Durigan Junior ]
  * d/p/openldap-create-ldap-URLs-correctly-for-IPv6-addresses.patch:
    (Closes: #1053643)

  [ Guilherme Puida Moreira ]
  * Add patches to fix CVE-2024-2004 and CVE-2024-2398.
    - CVE-2024-2004: When a protocol selection parameter disables all
      protocols without adding any then the default set of protocols would
      remain in the allowed set due to an error in the logic for removing
      protocols.
    - CVE-2024-2398: When an application tells libcurl it wants to allow
      HTTP/2 server push and the amount of received headers for the push
      surpasses the maximum allowed limit (1000), libcurl aborts the server
      push and leaks the memory allocated for the previously allocated
      headers.
  * d/p/openldap-create-ldap-URLs-correctly-for-IPv6-addresses.patch:
    Refresh patch.

[dgit import unpatched curl 7.88.1-10+deb12u6]
72 files changed:
debian/README.source
debian/changelog
debian/control
debian/copyright
debian/curl.install
debian/curl.manpages
debian/gbp.conf
debian/libcurl3-gnutls.install
debian/libcurl3-gnutls.links
debian/libcurl3-gnutls.lintian-overrides
debian/libcurl3-gnutls.symbols
debian/libcurl3-nss.install
debian/libcurl3-nss.links
debian/libcurl3-nss.lintian-overrides
debian/libcurl3-nss.symbols
debian/libcurl4-doc.docs
debian/libcurl4-doc.examples
debian/libcurl4-doc.links
debian/libcurl4-doc.manpages
debian/libcurl4-gnutls-dev.install
debian/libcurl4-gnutls-dev.links
debian/libcurl4-gnutls-dev.manpages
debian/libcurl4-nss-dev.install
debian/libcurl4-nss-dev.links
debian/libcurl4-nss-dev.manpages
debian/libcurl4-openssl-dev.install
debian/libcurl4-openssl-dev.manpages
debian/libcurl4.install
debian/libcurl4.symbols
debian/patches/04_workaround_as_needed_bug.patch
debian/patches/08_enable-zsh.patch
debian/patches/11_omit-directories-from-config.patch
debian/patches/90_gnutls.patch
debian/patches/99_nss.patch
debian/patches/CVE-2023-27533.patch
debian/patches/CVE-2023-27534.patch
debian/patches/CVE-2023-27535.patch
debian/patches/CVE-2023-27536.patch
debian/patches/CVE-2023-27537.patch
debian/patches/CVE-2023-27538.patch
debian/patches/CVE-2023-28319.patch
debian/patches/CVE-2023-28320-1.patch
debian/patches/CVE-2023-28320.patch
debian/patches/CVE-2023-28321.patch
debian/patches/CVE-2023-28322.patch
debian/patches/CVE-2023-32001.patch
debian/patches/CVE-2023-38039.patch
debian/patches/CVE-2023-38545.patch
debian/patches/CVE-2023-38546.patch
debian/patches/CVE-2023-46218.patch
debian/patches/CVE-2023-46219.patch
debian/patches/CVE-2024-2004.patch
debian/patches/CVE-2024-2398.patch
debian/patches/Remove-curl-s-LDFLAGS-from-curl-config-static-libs.patch
debian/patches/Use-OpenLDAP-specific-functionality.patch
debian/patches/Use-correct-path-when-loading-libnss-pem-ckbi-.so.patch
debian/patches/build-Divide-mit-krb5-gssapi-link-flags-between-LDFLAGS-a.patch
debian/patches/fix-unix-domain-socket.patch
debian/patches/openldap-create-ldap-URLs-correctly-for-IPv6-addresses.patch
debian/patches/series
debian/rules
debian/salsa-ci.yml
debian/source/format
debian/tests/LDAP-bindata.c
debian/tests/control
debian/tests/curl-ldapi-test
debian/tests/upstream-tests-gnutls
debian/tests/upstream-tests-nss
debian/tests/upstream-tests-openssl
debian/upstream/metadata
debian/upstream/signing-key.asc
debian/watch