curl (7.88.1-10) unstable; urgency=medium
authorSamuel Henrique <samueloph@debian.org>
Thu, 18 May 2023 22:43:40 +0000 (23:43 +0100)
committerSamuel Henrique <samueloph@debian.org>
Thu, 18 May 2023 22:43:40 +0000 (23:43 +0100)
commit86918d9438c5941272cf452c85873294069708c8
tree6d2ea913ac0367c4cd5d498b9c164f1da9949e66
parent6f0dc41c18d1799ca7f24898807d967e97d75a9f
parent7dc4f17f135c6b28ff76647825452a9312e8477c
curl (7.88.1-10) unstable; urgency=medium

  * Add new patches to fix CVEs (closes: #1036239):
    - CVE-2023-28319: UAF in SSH sha256 fingerprint check
    - CVE-2023-28320: siglongjmp race condition
    - CVE-2023-28321: IDN wildcard match
    - CVE-2023-28322: more POST-after-PUT confusion
  * d/libcurl*.symbols: Drop curl_jmpenv, not built anymore due to
    CVE-2023-28320

[dgit import unpatched curl 7.88.1-10]
60 files changed:
debian/README.source
debian/changelog
debian/control
debian/copyright
debian/curl.install
debian/curl.manpages
debian/gbp.conf
debian/libcurl3-gnutls.install
debian/libcurl3-gnutls.links
debian/libcurl3-gnutls.lintian-overrides
debian/libcurl3-gnutls.symbols
debian/libcurl3-nss.install
debian/libcurl3-nss.links
debian/libcurl3-nss.lintian-overrides
debian/libcurl3-nss.symbols
debian/libcurl4-doc.docs
debian/libcurl4-doc.examples
debian/libcurl4-doc.links
debian/libcurl4-doc.manpages
debian/libcurl4-gnutls-dev.install
debian/libcurl4-gnutls-dev.links
debian/libcurl4-gnutls-dev.manpages
debian/libcurl4-nss-dev.install
debian/libcurl4-nss-dev.links
debian/libcurl4-nss-dev.manpages
debian/libcurl4-openssl-dev.install
debian/libcurl4-openssl-dev.manpages
debian/libcurl4.install
debian/libcurl4.symbols
debian/patches/04_workaround_as_needed_bug.patch
debian/patches/08_enable-zsh.patch
debian/patches/11_omit-directories-from-config.patch
debian/patches/90_gnutls.patch
debian/patches/99_nss.patch
debian/patches/CVE-2023-27533.patch
debian/patches/CVE-2023-27534.patch
debian/patches/CVE-2023-27535.patch
debian/patches/CVE-2023-27536.patch
debian/patches/CVE-2023-27537.patch
debian/patches/CVE-2023-27538.patch
debian/patches/CVE-2023-28319.patch
debian/patches/CVE-2023-28320-1.patch
debian/patches/CVE-2023-28320.patch
debian/patches/CVE-2023-28321.patch
debian/patches/CVE-2023-28322.patch
debian/patches/Remove-curl-s-LDFLAGS-from-curl-config-static-libs.patch
debian/patches/Use-correct-path-when-loading-libnss-pem-ckbi-.so.patch
debian/patches/build-Divide-mit-krb5-gssapi-link-flags-between-LDFLAGS-a.patch
debian/patches/fix-unix-domain-socket.patch
debian/patches/series
debian/rules
debian/salsa-ci.yml
debian/source/format
debian/tests/control
debian/tests/upstream-tests-gnutls
debian/tests/upstream-tests-nss
debian/tests/upstream-tests-openssl
debian/upstream/metadata
debian/upstream/signing-key.asc
debian/watch