-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 02 Jan 2025 21:11:56 -0300 Source: curl Binary: curl curl-dbgsym libcurl3-gnutls libcurl3-gnutls-dbgsym libcurl3-nss libcurl3-nss-dbgsym libcurl4 libcurl4-dbgsym libcurl4-gnutls-dev libcurl4-nss-dev libcurl4-openssl-dev Architecture: ppc64el Version: 7.88.1-10+deb12u9 Distribution: bookworm Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-osuosl-02) Changed-By: Aquila Macedo Costa Description: curl - command line tool for transferring data with URL syntax libcurl3-gnutls - easy-to-use client-side URL transfer library (GnuTLS flavour) libcurl3-nss - easy-to-use client-side URL transfer library (NSS flavour) libcurl4 - easy-to-use client-side URL transfer library (OpenSSL flavour) libcurl4-gnutls-dev - development files and documentation for libcurl (GnuTLS flavour) libcurl4-nss-dev - development files and documentation for libcurl (NSS flavour) libcurl4-openssl-dev - development files and documentation for libcurl (OpenSSL flavour) Changes: curl (7.88.1-10+deb12u9) bookworm; urgency=medium . * Team upload. * Import patches for CVE-2024-9681 - A vulnerability in curl's HSTS handling allows a subdomain’s expiry time to overwrite its parent domain’s cache entry. This can lead to unintended HTTPS upgrades or premature reversion to HTTP when both subdomains and parent domains are used. Affects applications with HSTS enabled, potentially disrupting access when a domain stops supporting HTTPS. * d/patches: - CVE-2024-9681-*.patch: Backport patches. - CVE-2024-9681-1: fix backport inconsistencies - large-time-testable-feature.patch: Import 'large-time' feature for tests - dont-stop-stunnel-before-retry.patch: Import patch to avoid stopping stunnel before retrying Checksums-Sha1: d48258187d01b83b9ff97f9a266498d1343a9fa9 163536 curl-dbgsym_7.88.1-10+deb12u9_ppc64el.deb 601e759a86df8e3380755147dedd283ba0aee1f6 13087 curl_7.88.1-10+deb12u9_ppc64el-buildd.buildinfo 4e5736c387285e97586c8278572300156c2630a1 315868 curl_7.88.1-10+deb12u9_ppc64el.deb 257505cef6f9540793e8aa9620cf6bb9c16ed8ac 1046884 libcurl3-gnutls-dbgsym_7.88.1-10+deb12u9_ppc64el.deb e875683dac37775bf634648551215e26d5d94288 406480 libcurl3-gnutls_7.88.1-10+deb12u9_ppc64el.deb e3f79715266049e36e925ef46d54620f67612fa1 1091440 libcurl3-nss-dbgsym_7.88.1-10+deb12u9_ppc64el.deb 8f05236c8c2c98a958f70f184cb53ced640fd97f 417016 libcurl3-nss_7.88.1-10+deb12u9_ppc64el.deb ea64e3684fb7b63499d8bd7c417f3501a9230a49 1075792 libcurl4-dbgsym_7.88.1-10+deb12u9_ppc64el.deb a870742755fe40f2c6308cb5af122f13418a0115 517536 libcurl4-gnutls-dev_7.88.1-10+deb12u9_ppc64el.deb 534ebbe3a47458eab6ccecf7e5f914c4a2389e91 528796 libcurl4-nss-dev_7.88.1-10+deb12u9_ppc64el.deb 26d9509b0cd04da46ac9fe1910605109b0c009dc 522436 libcurl4-openssl-dev_7.88.1-10+deb12u9_ppc64el.deb 4098ada4b578886573f1e2298717ac1fad4088ad 410744 libcurl4_7.88.1-10+deb12u9_ppc64el.deb Checksums-Sha256: 3794194f205ba02724fe252b85804d51187d0372858835000c870cba2d11f50b 163536 curl-dbgsym_7.88.1-10+deb12u9_ppc64el.deb 3fe44c27b5a37516c50113d585c6f93bcb795d8a381b443a61a350571e712a6d 13087 curl_7.88.1-10+deb12u9_ppc64el-buildd.buildinfo 1fd547e54ae8fe7edb9ca9d917899578e7ff0e821a979fbd5bcd0c93b09529c4 315868 curl_7.88.1-10+deb12u9_ppc64el.deb 3d588d24344d4447a3565e69a2a114853c4b64978395726b497dbc88fd67abb7 1046884 libcurl3-gnutls-dbgsym_7.88.1-10+deb12u9_ppc64el.deb c8747a46702e926aa64cc92f139d02af72fa03d145798600e057a80aefd9ba4c 406480 libcurl3-gnutls_7.88.1-10+deb12u9_ppc64el.deb 2df428fb7e28ec0279265c8cd1d665ff159180a701ed6dd354f0ba18230b4e75 1091440 libcurl3-nss-dbgsym_7.88.1-10+deb12u9_ppc64el.deb edea977aaae2f712e0911f01168926d07c2e203f1b0900ef6cdff058241dfe15 417016 libcurl3-nss_7.88.1-10+deb12u9_ppc64el.deb 193557f7a9a83f8e65b3ac5d19195facfb200e0ffc7aedbdb1babb0f8a4a3d8d 1075792 libcurl4-dbgsym_7.88.1-10+deb12u9_ppc64el.deb 15165cd17e819bc989408f8ec6b5a39f074383f322d2d49a150361fb8403e2a2 517536 libcurl4-gnutls-dev_7.88.1-10+deb12u9_ppc64el.deb e51765578b655d3894eb683a7cfd884282f96e2941ff6cab86bfb9f65e211825 528796 libcurl4-nss-dev_7.88.1-10+deb12u9_ppc64el.deb 377e27fb6038cc9a9d07e9477042cf5eb9a0e6e200754ff5f18e66423c65a8e7 522436 libcurl4-openssl-dev_7.88.1-10+deb12u9_ppc64el.deb ee6d376cf6b2d75bad13254b22c35e854b0cd3ded3d9a3723f081f6bbdb1f9ae 410744 libcurl4_7.88.1-10+deb12u9_ppc64el.deb Files: dc4e00d797800cb482c9c0f09bf9cfde 163536 debug optional curl-dbgsym_7.88.1-10+deb12u9_ppc64el.deb a1047886fe2cd5a1c5cbf2390ff376a3 13087 web optional curl_7.88.1-10+deb12u9_ppc64el-buildd.buildinfo e7bc3f23f5e8b5ac9008776f1025423b 315868 web optional curl_7.88.1-10+deb12u9_ppc64el.deb 4ae619846563a1b18db3710078ddab77 1046884 debug optional libcurl3-gnutls-dbgsym_7.88.1-10+deb12u9_ppc64el.deb 109d001852320d67edc4a4b4ee13a9e1 406480 libs optional libcurl3-gnutls_7.88.1-10+deb12u9_ppc64el.deb efd631c2ce9a2450c36233c88d9a828f 1091440 debug optional libcurl3-nss-dbgsym_7.88.1-10+deb12u9_ppc64el.deb 6d9b8805927d76a0c4d22377cd59d36e 417016 libs optional libcurl3-nss_7.88.1-10+deb12u9_ppc64el.deb f023e5a9d8efda9eb0f2383484237a14 1075792 debug optional libcurl4-dbgsym_7.88.1-10+deb12u9_ppc64el.deb aa4c635df3e9f2da9f97274e73dca70c 517536 libdevel optional libcurl4-gnutls-dev_7.88.1-10+deb12u9_ppc64el.deb aa723dc4582e60aa305ebaaf8f00ed44 528796 libdevel optional libcurl4-nss-dev_7.88.1-10+deb12u9_ppc64el.deb 246958823bb1898e307ec103040bf4ad 522436 libdevel optional libcurl4-openssl-dev_7.88.1-10+deb12u9_ppc64el.deb f7092d4408e9857375632a3015ac7611 410744 libs optional libcurl4_7.88.1-10+deb12u9_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE0YcVZfZCWQv84jpRNcqbeolus3sFAmeVKCEACgkQNcqbeolu s3uAtw/+MgcxwQrWAlDh4sN8ITlBJLzeOWunTUnQd8cmJB2qr3+sqapsypuCafd7 t213OOXvErvhLPhHoc8x5Ca08b0CSsE9wm8ORyr7CeVt+uHZ9EzoM8QnR+NeGRqr RiRa3f3qb0mEitUsbTLrKMtUbYC5PAiFtlL1WWe8iPZqmNPzzZyHdkyAnCJuRejF oVvekZw4li7lyj8qrf2fs8GwzanHC3AhDeQ2hlpgGLU2HbRkjf9TCF4OR07hRcHA CgqwjlpxKahiRYdHJoQ5syZFI0QvrKOMl/l5F7qa7jb8t4VlXIXVBWTwCBJhLGRN AAWXNOOrd3f1Eq6Io/c+VzRHRLspkdpQ7EF8eK8jSl9N8Xi5Ab4GDCu2e5qGMMEs X1YRQR4W0tpo07KZ2/yZK+6OZLJwxqtQGRKuq+52GkKpx4VTtDfpn3LW1QQfOXaW 4oQBj2kT68lnGJLG2vm2a60UKZ00TvVRdnIZh1WCgAjkQb2UN8bLgEFWYlatJ8z4 q/SSI98BN/CYbD+oqAORRz5bvnvCAJERqGZpD8wbe8b77MexkIhpPuxQTngIVsQL 3lxuOEftaQVjCQnMCSi88h9fNLjsfGr0X0RUhr3MTFrOhM9dTTYv2wFinejQCHUQ G3AJC7nStCVzpl55/5Mfusyu96CqsS5nkvzS6gtLnqZT6ohdUCY= =jx6y -----END PGP SIGNATURE-----