Last commit made on 2019-09-11
Get this branch:
git clone -b applied/ubuntu/xenial-devel https://git.launchpad.net/ubuntu/+source/curl
Members of Ubuntu Server Dev import team can upload to this branch. Log in for directions.

Branch merges

Branch information


Recent commits

fbbf775... by Alex Murray on 2019-09-06

Import patches-applied version 7.47.0-1ubuntu2.14 to applied/ubuntu/xenial-security

Imported using git-ubuntu import.

Changelog parent: dbb3afb8f015476824c22d84cbcd6c453f742885
Unapplied parent: 46bd4dd600f86dc7d3526e57d52a6137ee48a38e

New changelog entries:
  * SECURITY UPDATE: double-free when using kerberos over FTP may cause
    - debian/patches/CVE-2019-5481.patch: update lib/security.c to avoid
      double-free on large memory allocation failures
    - CVE-2019-5481
  * SECURITY UPDATE: heap buffer overflow when receiving TFTP data may
    cause denial-of-service or remote code-execution
    - debian/patches/CVE-2019-5482.patch: ensure to use the correct block
      size when calling recvfrom() if the server returns an OACK without
      specifying a block size in lib/tftp.c
    - CVE-2019-5482

46bd4dd... by Alex Murray on 2019-09-06

Build with NSS.

Gbp-Pq: 99_nss.patch.

345ba8d... by Alex Murray on 2019-09-06

Build with GnuTLS.

Gbp-Pq: 90_gnutls.patch.

e63cfb5... by Alex Murray on 2019-09-06

[PATCH] tftp: Alloc maximum blksize, and use default unless OACK is

Gbp-Pq: CVE-2019-5482.patch.

f73bbba... by Alex Murray on 2019-09-06

[PATCH] security:read_data fix bad realloc()

Gbp-Pq: CVE-2019-5481.patch.

645eb23... by Alex Murray on 2019-09-06

[PATCH] tftp: use the current blksize for recvfrom()

Gbp-Pq: CVE-2019-5436.patch.

0000c5a... by Alex Murray on 2019-09-06

[PATCH 3/3] smtp: avoid risk of buffer overflow in strtol

Gbp-Pq: CVE-2019-3823.patch.

0489f95... by Alex Murray on 2019-09-06

[PATCH 2/3] ntlm: fix *_type3_message size check to avoid buffer

Gbp-Pq: CVE-2019-3822.patch.

5556cd5... by Alex Murray on 2019-09-06

[PATCH 1/3] NTLM: fix size check condition for type2 received data

Gbp-Pq: CVE-2018-16890.patch.

8c13426... by Alex Murray on 2019-09-06

[PATCH] voutf: fix bad arethmetic when outputting warnings to stderr

Gbp-Pq: oob-read.patch.