New Debian curl 7.88.1-10+deb12u14 fixes: This update addresses the following issues: * curl: HSTS subdomain overwrites parent cache entry (CVE-2024-9681) * curl: curl netrc password leak (CVE-2024-11053) * When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance. (CVE-2025-0167) 7.88.1-10+deb12u14 (Sat, 19 Jul 2025 21:04:59 +0200) * d/p/0001-http_chunks-reset...: New patch to fix memory leak: - Thanks to Daniel Stenberg and dheerajsangamkar for reporting the issue and writing a patch 7.88.1-10+deb12u13 (Mon, 16 Jun 2025 20:56:01 -0300) * Team upload. * debian/patches/fix-CVE-2023-27534-regression-{1,2}.patch: add patches from upstream to restore sftp://host/~ behaviour.
--- mirror/ftp/pool/main/c/curl/curl_7.88.1-10+deb12u12.dsc +++ apt/ucs_5.2-0-errata5.2-3/source/curl_7.88.1-10+deb12u14.dsc @@ -1,3 +1,15 @@ +7.88.1-10+deb12u14 [Sat, 19 Jul 2025 21:04:59 +0200] Samuel Henrique <samueloph@debian.org>: + + * d/p/0001-http_chunks-reset...: New patch to fix memory leak: + - Thanks to Daniel Stenberg and dheerajsangamkar for reporting the issue + and writing a patch + +7.88.1-10+deb12u13 [Mon, 16 Jun 2025 20:56:01 -0300] Carlos Henrique Lima Melara <charlesmelara@riseup.net>: + + * Team upload. + * debian/patches/fix-CVE-2023-27534-regression-{1,2}.patch: add patches from + upstream to restore sftp://host/~ behaviour. + 7.88.1-10+deb12u12 [Sun, 09 Mar 2025 10:45:45 +0000] Samuel Henrique <samueloph@debian.org>: * d/p/runtests.pl-Increase-variance-of-random-seed-used-for-tes: Fix test <http://piuparts.knut.univention.de/5.2-3/#7229402300083255991>
OK: YAML OK: Tests OK: piuparts
<https://errata.software-univention.de/#/?erratum=5.2x188>