-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 02 Jan 2025 21:11:56 -0300 Source: curl Binary: curl curl-dbgsym libcurl3-gnutls libcurl3-gnutls-dbgsym libcurl3-nss libcurl3-nss-dbgsym libcurl4 libcurl4-dbgsym libcurl4-gnutls-dev libcurl4-nss-dev libcurl4-openssl-dev Architecture: armhf Version: 7.88.1-10+deb12u9 Distribution: bookworm Urgency: medium Maintainer: arm Build Daemon (arm-ubc-02) Changed-By: Aquila Macedo Costa Description: curl - command line tool for transferring data with URL syntax libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.88.1-10+deb12u9) bookworm; urgency=medium . * Team upload. * Import patches for CVE-2024-9681 - A vulnerability in curl's HSTS handling allows a subdomain’s expiry time to overwrite its parent domain’s cache entry. This can lead to unintended HTTPS upgrades or premature reversion to HTTP when both subdomains and parent domains are used. Affects applications with HSTS enabled, potentially disrupting access when a domain stops supporting HTTPS. * d/patches: - CVE-2024-9681-*.patch: Backport patches. - CVE-2024-9681-1: fix backport inconsistencies - large-time-testable-feature.patch: Import 'large-time' feature for tests - dont-stop-stunnel-before-retry.patch: Import patch to avoid stopping stunnel before retrying Checksums-Sha1: c79d26b2f433caac67986005c044468a3a6b706d 159076 curl-dbgsym_7.88.1-10+deb12u9_armhf.deb ff059336a576181d8bba4a20c5ffbfa0da5480db 12929 curl_7.88.1-10+deb12u9_armhf-buildd.buildinfo 85967e5782d5236d25b492be61524e43300c635d 305768 curl_7.88.1-10+deb12u9_armhf.deb a13f59b164b4db48454ee728a3e46046066f557f 1001012 libcurl3-gnutls-dbgsym_7.88.1-10+deb12u9_armhf.deb d5f6ff3119edf07990e035b325edc96105025310 346084 libcurl3-gnutls_7.88.1-10+deb12u9_armhf.deb e4a04d2c175eb12e16400bb46452fb466cca9098 1046316 libcurl3-nss-dbgsym_7.88.1-10+deb12u9_armhf.deb cefcc111521587b6966ccca0eaddd7a27241db0f 353228 libcurl3-nss_7.88.1-10+deb12u9_armhf.deb 87bbacc48a08f7f8c695875360abe97d0d12f5a2 1026944 libcurl4-dbgsym_7.88.1-10+deb12u9_armhf.deb 3c8de1f0cc422f72f02371c8c6c472c1b01bfe3d 451852 libcurl4-gnutls-dev_7.88.1-10+deb12u9_armhf.deb 448fe779ab89fb0b985006a709308bddbd683683 459964 libcurl4-nss-dev_7.88.1-10+deb12u9_armhf.deb a5e9ac3034c076807356a4a73fda1868fb54aba9 457056 libcurl4-openssl-dev_7.88.1-10+deb12u9_armhf.deb dcb5b4ae4c41243ff6cffc3382062f4d0cd400ab 350648 libcurl4_7.88.1-10+deb12u9_armhf.deb Checksums-Sha256: 2de5e496a88efaec390a6940f2066cee388030da1b73e71eea52058c0ffafa6d 159076 curl-dbgsym_7.88.1-10+deb12u9_armhf.deb 92f122e459c1ac465f751ac584435a95aef94129483e1ceaaf134974922d3176 12929 curl_7.88.1-10+deb12u9_armhf-buildd.buildinfo f7b1efcd4d4a1a4a62e74093304cec6d340999e63142db9e37dd824037dbc03c 305768 curl_7.88.1-10+deb12u9_armhf.deb 5d009c5aff9808519b1d3c063d7a1bca9191f48cba0bef399b37ab20a3091bdb 1001012 libcurl3-gnutls-dbgsym_7.88.1-10+deb12u9_armhf.deb 52cce373d8dc79f3ea513b0577f8be1d7d3f6ca0eeac7beed40b84b7a23a3f8c 346084 libcurl3-gnutls_7.88.1-10+deb12u9_armhf.deb 6bc4c60d8136c4c5583d93d4389c8b16619bbe7fb5b6077527639aadd1881b9e 1046316 libcurl3-nss-dbgsym_7.88.1-10+deb12u9_armhf.deb f11bf4aea36958e83f148b443a0a1594cd68d13d8b23e1353f84002d290a2d7a 353228 libcurl3-nss_7.88.1-10+deb12u9_armhf.deb e439d1b992ebfd88eb8ef83b5533dd1eb58ab166d9b674856eb204fe5cfce42a 1026944 libcurl4-dbgsym_7.88.1-10+deb12u9_armhf.deb f84a7e57383700dba67559348a7cb33ccda8480472cce58c5a951ad2d5fd5737 451852 libcurl4-gnutls-dev_7.88.1-10+deb12u9_armhf.deb 6cde48827e4a1b5026c572d38e77edf91fc42137822e75dfa952cf9a909bdfab 459964 libcurl4-nss-dev_7.88.1-10+deb12u9_armhf.deb ca795f0002cb4c509cfad7d53cb29554755ec2b24675c0c14d66fb488f38807c 457056 libcurl4-openssl-dev_7.88.1-10+deb12u9_armhf.deb 9e85b0b042505ba617093dfb570275df7988f59f5083639d62190de12f4a011c 350648 libcurl4_7.88.1-10+deb12u9_armhf.deb Files: 582c377a88731ecb6db79f1c881b2a17 159076 debug optional curl-dbgsym_7.88.1-10+deb12u9_armhf.deb e6255fd2880c1fbce99763389c0e5c68 12929 web optional curl_7.88.1-10+deb12u9_armhf-buildd.buildinfo 397b098154f29992912e22e19e541877 305768 web optional curl_7.88.1-10+deb12u9_armhf.deb 5e43029235335001f2237d317d4cc84b 1001012 debug optional libcurl3-gnutls-dbgsym_7.88.1-10+deb12u9_armhf.deb ae6b223acb3a0638044e25d9e3840b39 346084 libs optional libcurl3-gnutls_7.88.1-10+deb12u9_armhf.deb 879bb94d1da9fd539be1473b27777eb2 1046316 debug optional libcurl3-nss-dbgsym_7.88.1-10+deb12u9_armhf.deb f6b345e40488954b4ec1a22922e29e14 353228 libs optional libcurl3-nss_7.88.1-10+deb12u9_armhf.deb fa74ecab2bd13b5ca54d67514412f359 1026944 debug optional libcurl4-dbgsym_7.88.1-10+deb12u9_armhf.deb 2a981254c2e5442767932ca5aa8a6e8f 451852 libdevel optional libcurl4-gnutls-dev_7.88.1-10+deb12u9_armhf.deb 22232bc34ae7c87d01dd9662e3a46f51 459964 libdevel optional libcurl4-nss-dev_7.88.1-10+deb12u9_armhf.deb 1823fd2a3a74de42b4d649606a0509be 457056 libdevel optional libcurl4-openssl-dev_7.88.1-10+deb12u9_armhf.deb 5f6826a51212aa05c681f26cd5004a48 350648 libs optional libcurl4_7.88.1-10+deb12u9_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE9C4sZYDxwNo9XoUDaRWK3AIe28EFAmeVNAUACgkQaRWK3AIe 28EEOA/9G/eB01N3evyt/MfqG3GKq9MH+rwf7ZsaCDkgieGNPDRE2fCmY0Flot+z Rw1P5sofQHq1RfwqXsCn0eXtZ+EFq4bXMfEyRGRW8ZBF95Hbe47axXQHLtNzCxKb G0xSKifIPO/XhhPL3brGKrC9zFllvBrUfN7eK+/71fWfw3dtBP7/9L/6ssaIfsGo DDsUTZ5O9aLP3cKe3ncb9/2itSR4eyi/49LY0kXgV73I1pRB+k9xF3iK4Ij+OUX2 sH/pEJwmagplt2fD0OkJYnp/hVFTs4oAo3Owioc0qVOswh/PpwSZomDxbWhdy524 uiW0j3rMDyJ3NsRSvvWsYXczkdUM1ORTQ0Rq8WVSo6HG2RUNzg7CdM7YIBpSBSVy hfrGw4C5eLUISLyCZG7nklw4nz5f+3EBvg1ysjNHuP0GmpVJGMmTbcOLsTDw+crM nOgBheMBoykGRp/nSGNeXMHfHtHxQPEtgBy8ht66ZVJ+fbRSfrc2ejm7+alaZPu4 dfcvljLx84+6N3G7UtFBI/p5wlVmDBe2ONrZ8cA2wUp6PnU66XAd4yVLxv4tktZd OwPJDzSq7Hm6R1WN5KNEdBJ75myEgmeWdWBRnxeQ+jYmmhOyPnldXprHeXs5RRRp MxQrxAJ8duvjMZguqjFD3qvvHAT7yAeUvPNxyfHJdqRhw0dwP6Y= =tUrf -----END PGP SIGNATURE-----