From: Raspbian automatic forward porter Date: Mon, 5 Jun 2023 04:33:19 +0000 (+0100) Subject: Merge version 7.88.1-9+rpi1 and 7.88.1-10 to produce 7.88.1-10+rpi1 X-Git-Tag: archive/raspbian/7.88.1-10+rpi1^0 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=8eee2e9974879727df491ce545bb0832566565d4;p=curl.git Merge version 7.88.1-9+rpi1 and 7.88.1-10 to produce 7.88.1-10+rpi1 --- 8eee2e9974879727df491ce545bb0832566565d4 diff --cc debian/changelog index 14d3036f,f420a8af..4b6a61c4 --- a/debian/changelog +++ b/debian/changelog @@@ -1,8 -1,14 +1,21 @@@ - curl (7.88.1-9+rpi1) bookworm-staging; urgency=medium ++curl (7.88.1-10+rpi1) bookworm-staging; urgency=medium + ++ [changes brought forward from 7.88.1-9+rpi1 by Peter Michael Green at Sat, 20 May 2023 09:55:44 +0000] + * Disable testsuite. + - -- Peter Michael Green Sat, 20 May 2023 09:55:44 +0000 ++ -- Raspbian forward porter Mon, 05 Jun 2023 04:33:19 +0000 ++ + curl (7.88.1-10) unstable; urgency=medium + + * Add new patches to fix CVEs (closes: #1036239): + - CVE-2023-28319: UAF in SSH sha256 fingerprint check + - CVE-2023-28320: siglongjmp race condition + - CVE-2023-28321: IDN wildcard match + - CVE-2023-28322: more POST-after-PUT confusion + * d/libcurl*.symbols: Drop curl_jmpenv, not built anymore due to + CVE-2023-28320 + + -- Samuel Henrique Thu, 18 May 2023 23:43:40 +0100 curl (7.88.1-9) unstable; urgency=medium