lp:ubuntu/oneiric-security/curl

Created by Ubuntu Package Importer on 2012-01-24 and last modified on 2013-04-11
Get this branch:
bzr branch lp:ubuntu/oneiric-security/curl
Members of Ubuntu branches can upload to this branch. Log in for directions.

Branch merges

Related bugs

Related blueprints

Branch information

Owner:
Ubuntu branches
Review team:
Ubuntu Development Team
Status:
Mature

Recent revisions

55. By Seth Arnold on 2013-04-11

* SECURITY UPDATE: Incorrect cookie domain handling in tailmatch()
  - debian/patches/curl-tailmatch.patch: enforce strict subdomain match
    when sending cookies. Patch from YAMADA Yasuharu.
  - http://curl.haxx.se/curl-tailmatch.patch
  - CVE-2013-1944

54. By Marc Deslauriers on 2012-01-24

* SECURITY UPDATE: URL sanitization vulnerability
  - debian/patches/CVE-2012-0036.patch: reject URLs with embedded control
    codes in lib/{escape.h,escape.c,imap.c,pop3.c,smtp.c}.
  - CVE-2012-0036

53. By James Page on 2011-09-14

[ James Page, Colin Watson ]
Add new libcurl3-udeb package, stripped down for use during installation
(LP: #831496).

52. By Jamie Strandboge on 2011-07-13

debian/patches/timeout_bug_736216: cherry pick upstream
git revision d4e000906ac4ef243258a5c9a819a7cde247d16a to fix
handshake timeout bug (LP: #736216). Thanks to Sidnei da Silva
and Michael Vogt

51. By Steve Langasek on 2011-06-30

* Restore Ubuntu changes accidentally dropped in previous sync:
  - Drop dependencies not in main:
    + Build-Depends: Replace libssh2-1-dev with openssh-server.
      Drop stunnel since it's in universe, as well.
    + Drop libssh2-1-dev from libcurl4-openssl-dev's Depends.

50. By Ramakrishnan Muthukrishnan on 2011-06-29

Apply the Multiarch patch from Steve Langasek.
(closes: #631946)

49. By Steve Langasek on 2011-05-06

releasing version 7.21.6-1ubuntu2

48. By Steve Langasek on 2011-05-06

merge multiarch support

47. By Lorenzo De Liso on 2011-05-02

* Merge from debian unstable (LP: #775794), remaining changes:
  - debian/control:
    + Build-Depends: Replace libssh2-1-dev with openssh-server.
      Drop stunnel since it's in universe, as well.
    + Drop libssh2-1-dev from libcurl4-openssl-dev's Depends.

46. By Artur Rona on 2011-01-26

* Merge from debian unstable. Remaining changes: (LP: #707756)
  - debian/control:
    + Build-Depends: Replace libssh2-1-dev with openssh-server.
      Drop stunnel since it's in universe, as well.
    + Drop libssh2-1-dev from libcurl4-openssl-dev's Depends.
    Above changes are necessary to be independent from the universe.

Branch metadata

Branch format:
Branch format 7
Repository format:
Bazaar repository format 2a (needs bzr 1.16 or later)
Stacked on:
lp:ubuntu/precise/curl
This branch contains Public information 
Everyone can see this information.

Subscribers