lp:debian/jessie/curl

Created by Ubuntu Package Importer and last modified
Get this branch:
bzr branch lp:debian/jessie/curl
Members of Ubuntu branches can upload to this branch. Log in for directions.

Related bugs

Related blueprints

Branch information

Owner:
Ubuntu branches
Status:
Development

Recent revisions

61. By Alessandro Ghedini

Don't send sensitive HTTP server headers to proxies as per CVE-2015-3153
http://curl.haxx.se/docs/adv_20150429.html

60. By Alessandro Ghedini

* Fix URL request injection vulnerability as per CVE-2014-8150
  http://curl.haxx.se/docs/adv_20150108B.html
* Set urgency=high accordingly

59. By Alessandro Ghedini

* Enable all hardening options (Closes: #763372)
* Fix duphandle read out of bounds as per CVE-2014-3707
  http://curl.haxx.se/docs/adv_20141105.html
* Set urgency=high accordingly

58. By Alessandro Ghedini

* Check for libtoolize instead of libtool during build.
  Thanks to Helmut Grohne for the patch (Closes: #761740)
* Add README.source note regarding ordering of patches (Closes: #762193)
* Add 10_fix-resolver.patch from upstream (Closes: #762014)

57. By Alessandro Ghedini

* New upstream release
  - Only use full host matches for hosts used as IP address
    as per CVE-2014-3613
    http://curl.haxx.se/docs/adv_20140910A.html
  - Reject incoming cookies set for TLDs as per CVE-2014-3620
    http://curl.haxx.se/docs/adv_20140910B.html
* Drop 08_link-curl-to-nss.patch (merged upstream)
* Refresh patches
* Fix wildcard-matches-nothing-in-dep5-copyright
* Add 08_fix-spelling.patch

56. By Alessandro Ghedini

* New upstream release
* Re-enable RTMP support (Closes: #754222)
* Add 08_link-curl-to-nss.patch to fix NSS build
* Refresh patches
* Install manpages of single libcurl options too

55. By Alessandro Ghedini

* New upstream release
  - Fix NULL pointer dereference in GnuTLS code (Closes: #746349)
* Drop 08_fix-imap-tests.patch (merged upstream)
* Refresh 01_runtests_gdb.patch
* Remove Build-Depends on libgcrypt

54. By Alessandro Ghedini

* Move Depends on -dev packages needed to use static libraries to Suggests
* Switch to GnuTLS 3.x (Closes: #741568)
* Disable RTMP support (librtmp-dev requires libgnutls-dev, which conflicts
  with libgnutls28-dev)

53. By Alessandro Ghedini

* New upstream release (Closes: #742728)
  - Fix connection re-use when using different log-in credentials
    as per CVE-2014-0138
    http://curl.haxx.se/docs/adv_20140326A.html
  - Reject IP address wildcard matches as per CVE-2014-0139
    http://curl.haxx.se/docs/adv_20140326B.html
  - Set urgency=high accordingly
* Add 08_fix-imap-tests.patch to fix tests broken by the fix for CVE-2014-0138

52. By Alessandro Ghedini

* New upstream release
  - Fix re-use of wrong HTTP NTLM connection as per CVE-2014-0015
    http://curl.haxx.se/docs/adv_20140129.html
  - Set urgency=high accordingly
* Refresh patches

Branch metadata

Branch format:
Branch format 7
Repository format:
Bazaar repository format 2a (needs bzr 1.16 or later)
Stacked on:
lp:debian/curl
This branch contains Public information 
Everyone can see this information.

Subscribers