curl 7.38.0-3ubuntu1 source package in Ubuntu

Changelog

curl (7.38.0-3ubuntu1) vivid; urgency=medium

  * Merge from Debian. Remaining changes:
    - Drop dependencies not in main:
      + Build-Depends: Drop stunnel4 and libssh2-1-dev.
      + Drop libssh2-1-dev from binary package Depends.
    - Add new libcurl3-udeb package.
    - Add new curl-udeb package.
  * Dropped patches:
    - debian/patches/09_fix-timeout-in-poll-and-wait.patch: upstream
    - debian/patches/CVE-2014-3613.patch: upstream
    - debian/patches/CVE-2014-3620.patch: upstream

curl (7.38.0-3) unstable; urgency=high

  * Enable all hardening options (Closes: #763372)
  * Fix duphandle read out of bounds as per CVE-2014-3707
    http://curl.haxx.se/docs/adv_20141105.html
  * Set urgency=high accordingly

curl (7.38.0-2) unstable; urgency=medium

  * Check for libtoolize instead of libtool during build.
    Thanks to Helmut Grohne for the patch (Closes: #761740)
  * Add README.source note regarding ordering of patches (Closes: #762193)
  * Add 10_fix-resolver.patch from upstream (Closes: #762014)

curl (7.38.0-1) unstable; urgency=medium

  * New upstream release
    - Only use full host matches for hosts used as IP address
      as per CVE-2014-3613
      http://curl.haxx.se/docs/adv_20140910A.html
    - Reject incoming cookies set for TLDs as per CVE-2014-3620
      http://curl.haxx.se/docs/adv_20140910B.html
  * Drop 08_link-curl-to-nss.patch (merged upstream)
  * Refresh patches
  * Fix wildcard-matches-nothing-in-dep5-copyright
  * Add 08_fix-spelling.patch
 -- Marc Deslauriers <email address hidden>   Mon, 10 Nov 2014 08:48:21 -0500

Upload details

Uploaded by:
Marc Deslauriers
Uploaded to:
Vivid
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
web
Urgency:
Very Urgent

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
curl_7.38.0.orig.tar.gz 3.9 MiB 5661028aa6532882fa228cd23c99ddbb8b87643dbb1a7ea55c068d34a943dff1
curl_7.38.0-3ubuntu1.debian.tar.xz 31.2 KiB 4b1311f22a4a3dc46422db369cc68de05052a566cdfa55efe7c934ef9c1f1227
curl_7.38.0-3ubuntu1.dsc 2.8 KiB eba5b8513f7d77439d1d687f8e130989a8abfd0841a7692d1092fbaba0391767

Available diffs

View changes file

Binary packages built by this source

curl: No summary available for curl in ubuntu vivid.

No description available for curl in ubuntu vivid.

curl-udeb: No summary available for curl-udeb in ubuntu vivid.

No description available for curl-udeb in ubuntu vivid.

libcurl3: No summary available for libcurl3 in ubuntu vivid.

No description available for libcurl3 in ubuntu vivid.

libcurl3-dbg: No summary available for libcurl3-dbg in ubuntu vivid.

No description available for libcurl3-dbg in ubuntu vivid.

libcurl3-gnutls: No summary available for libcurl3-gnutls in ubuntu vivid.

No description available for libcurl3-gnutls in ubuntu vivid.

libcurl3-nss: No summary available for libcurl3-nss in ubuntu vivid.

No description available for libcurl3-nss in ubuntu vivid.

libcurl3-udeb: No summary available for libcurl3-udeb in ubuntu vivid.

No description available for libcurl3-udeb in ubuntu vivid.

libcurl4-doc: No summary available for libcurl4-doc in ubuntu vivid.

No description available for libcurl4-doc in ubuntu vivid.

libcurl4-gnutls-dev: No summary available for libcurl4-gnutls-dev in ubuntu vivid.

No description available for libcurl4-gnutls-dev in ubuntu vivid.

libcurl4-nss-dev: No summary available for libcurl4-nss-dev in ubuntu vivid.

No description available for libcurl4-nss-dev in ubuntu vivid.

libcurl4-openssl-dev: No summary available for libcurl4-openssl-dev in ubuntu vivid.

No description available for libcurl4-openssl-dev in ubuntu vivid.