-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 02 Jan 2025 21:11:56 -0300 Source: curl Binary: curl curl-dbgsym libcurl3-gnutls libcurl3-gnutls-dbgsym libcurl3-nss libcurl3-nss-dbgsym libcurl4 libcurl4-dbgsym libcurl4-gnutls-dev libcurl4-nss-dev libcurl4-openssl-dev Architecture: mips64el Version: 7.88.1-10+deb12u9 Distribution: bookworm Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-04) Changed-By: Aquila Macedo Costa Description: curl - command line tool for transferring data with URL syntax libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.88.1-10+deb12u9) bookworm; urgency=medium . * Team upload. * Import patches for CVE-2024-9681 - A vulnerability in curl's HSTS handling allows a subdomain’s expiry time to overwrite its parent domain’s cache entry. This can lead to unintended HTTPS upgrades or premature reversion to HTTP when both subdomains and parent domains are used. Affects applications with HSTS enabled, potentially disrupting access when a domain stops supporting HTTPS. * d/patches: - CVE-2024-9681-*.patch: Backport patches. - CVE-2024-9681-1: fix backport inconsistencies - large-time-testable-feature.patch: Import 'large-time' feature for tests - dont-stop-stunnel-before-retry.patch: Import patch to avoid stopping stunnel before retrying Checksums-Sha1: b724fce2edb317655a11ddd592b97daeff30e213 165752 curl-dbgsym_7.88.1-10+deb12u9_mips64el.deb 1a5a1b3f498931f1073a9886432790b3fa53df07 12987 curl_7.88.1-10+deb12u9_mips64el-buildd.buildinfo a4c3b91bd5d30741e64018852a8b64289f1f9dc8 308856 curl_7.88.1-10+deb12u9_mips64el.deb 632386724a6139b7b4e63d3240919c2aa0a15265 1060292 libcurl3-gnutls-dbgsym_7.88.1-10+deb12u9_mips64el.deb 273ec10002964cac1cef6c9874e4f89cc21f17b3 355548 libcurl3-gnutls_7.88.1-10+deb12u9_mips64el.deb a157faaf6f937a897b7d7d352a686cbaa1766ba1 1106624 libcurl3-nss-dbgsym_7.88.1-10+deb12u9_mips64el.deb 7568563e32b8a35f593b91bd6df5ec59dc174792 363780 libcurl3-nss_7.88.1-10+deb12u9_mips64el.deb 78e3d6a7094682dbfc1c7715fad6ba19125714e2 1090552 libcurl4-dbgsym_7.88.1-10+deb12u9_mips64el.deb 1681f3726f96087a331c4f77c641c441bcb368ff 499744 libcurl4-gnutls-dev_7.88.1-10+deb12u9_mips64el.deb 92d138a40f5f1cc2ef729fce7abbe80d63a3fee0 508956 libcurl4-nss-dev_7.88.1-10+deb12u9_mips64el.deb d2819738c5615de783db2669a05fea7f4becc925 505452 libcurl4-openssl-dev_7.88.1-10+deb12u9_mips64el.deb 9df3b1cdbf2a34ed1b096f362899e173a6604c6b 360408 libcurl4_7.88.1-10+deb12u9_mips64el.deb Checksums-Sha256: 728d2cbf43a791b765fc798643e1af7d55a69e89ec0bad262c8aa3c31215abc4 165752 curl-dbgsym_7.88.1-10+deb12u9_mips64el.deb ec8aca76d1aa03729041d41749b6e09fc5123f9b17f5aacecf6073aaf7cb4365 12987 curl_7.88.1-10+deb12u9_mips64el-buildd.buildinfo 28609221aef5e1e1bca7f501a10eb16d3f305a8594347f334d7762145343acba 308856 curl_7.88.1-10+deb12u9_mips64el.deb 7e039196272fc9e63baf397e1541dcf94e6bda766f10dc5ef79877f1a245a7e9 1060292 libcurl3-gnutls-dbgsym_7.88.1-10+deb12u9_mips64el.deb f83c41192869e5e535f6f27926552c70762f564b8e523aff6190832944dabf24 355548 libcurl3-gnutls_7.88.1-10+deb12u9_mips64el.deb af174f775d9b3e98970fe43eba45c2797c2b20383c63ec6f79b758b9ed988a9b 1106624 libcurl3-nss-dbgsym_7.88.1-10+deb12u9_mips64el.deb 6a8cdf70650976718e9b0d1671f8c4b3cd0d76d8104f4abe2cebad8d00263065 363780 libcurl3-nss_7.88.1-10+deb12u9_mips64el.deb 44cc89b2a3b6eb7b7cbb4e8703e867ff05bfdee395867cf2af9251ccc973ebc1 1090552 libcurl4-dbgsym_7.88.1-10+deb12u9_mips64el.deb f7ee10ddf77f3610314e6cb45d92fb722d1490896c6c6619dc5037b782c17236 499744 libcurl4-gnutls-dev_7.88.1-10+deb12u9_mips64el.deb 197dd857fd1e424ae21b2b1c5c45303bd2b905b68ca4a966fc799c6f7a996528 508956 libcurl4-nss-dev_7.88.1-10+deb12u9_mips64el.deb 5cb40067cc7b64ed4d3643fdd3511988a6098c1a9a8ed90348d81f9f132d2a99 505452 libcurl4-openssl-dev_7.88.1-10+deb12u9_mips64el.deb 7901f6d7583e7dbe6c69587976aeca274c5e012fefbca72efa0a1914c6e0dd6d 360408 libcurl4_7.88.1-10+deb12u9_mips64el.deb Files: fa43df7e7c6d0f89ead2947f3f34110f 165752 debug optional curl-dbgsym_7.88.1-10+deb12u9_mips64el.deb 4d351d5205582a25fbd12583494e6d9a 12987 web optional curl_7.88.1-10+deb12u9_mips64el-buildd.buildinfo 54e1b65957e1740ea7cb1ce7d0fa8632 308856 web optional curl_7.88.1-10+deb12u9_mips64el.deb 67895ebd3c3db28faa91c46f545d6152 1060292 debug optional libcurl3-gnutls-dbgsym_7.88.1-10+deb12u9_mips64el.deb ce6f6b68d392222579eb3f3cd8ce8aa8 355548 libs optional libcurl3-gnutls_7.88.1-10+deb12u9_mips64el.deb 25d969c8a79408d40ed11edf6ba7c30b 1106624 debug optional libcurl3-nss-dbgsym_7.88.1-10+deb12u9_mips64el.deb 4f56dc4fd0327e7c2996cdf371ff5111 363780 libs optional libcurl3-nss_7.88.1-10+deb12u9_mips64el.deb 34c3540d02e722d39ea185e107c9f6ec 1090552 debug optional libcurl4-dbgsym_7.88.1-10+deb12u9_mips64el.deb e17a4242846fdcfc384eb200d5598e98 499744 libdevel optional libcurl4-gnutls-dev_7.88.1-10+deb12u9_mips64el.deb 77ca00a79c0c7a22a6f2ed6e1360cfd2 508956 libdevel optional libcurl4-nss-dev_7.88.1-10+deb12u9_mips64el.deb a61959129ccaaadb275059393be734bf 505452 libdevel optional libcurl4-openssl-dev_7.88.1-10+deb12u9_mips64el.deb 757524a86c25ba6979fba1f6c4aa0d8b 360408 libs optional libcurl4_7.88.1-10+deb12u9_mips64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERbXMbY9VMQqnSaVEV4aVsMglzVcFAmeVNKMACgkQV4aVsMgl zVcXYQ/+OSWufy6dDfdb8L/8IOEix/ajBr6PxAEvxYjzheiVzD5WVTnbHVzUIuaV t3CyjecyNfLU89zMoY/9bJb6QpTlyFHep8w4m6PsuFs3Ow3KZ55b5lbylGrZS1nO 3hclL8LMxJrPczb8yBQPvfWhmm2e9OV7KSZ9BM0QtR6dcG0LPE8Jv3vD7B2EaKoR NCbUxDrZUFzBypOOBtZ8Kc2rYdWWySRgrjs78xZStTqeFbjV1SmvEGUPRiXZ1SaI yWyxO8EWTCO2/Mk8LRynIDpWRd62qNAUfciLx0LIAB+PV2zqAJ0wef0IVhfOKi+p PjjYEDpSZq+zs2Z/YRSQOObiVgXeFy9WxXppcuo30MrPOhh0CNCaXSd2C0xDcIiW oY128k5WmuQm67JCHkjx6eSIs5hEs5OHIAmuknjpMfhKLCsstzbKe4kFmp0wM2ss qnK8MuW/HXe7dRENQ29yg7Qas1On1ZbW3sOQo2zSl5nNXC4eMRtFCA7I+ZCMquow C00c9I4Mc0oNzijPOCcRAJcZy9VD7pXy3nOU/pF3S6EJZXOA38ZRPLWfYv4mzflL u4wcRDaKU+2TCgOtgNHnfEqAKEdPpfL52Kfh2uV0I7QI2LmNDaTAphpeLnpYfq15 yFKgKjq4Y14E/sm1UXIJo8QOThJFg0swHl8EK7ZQuTuxiaYy8d8= =nsmF -----END PGP SIGNATURE-----