[ubuntu/plucky-proposed] curl 8.11.1-1ubuntu1 (Accepted)

Simon Quigley tsimonq2 at ubuntu.com
Sat Dec 14 09:40:13 UTC 2024


curl (8.11.1-1ubuntu1) plucky; urgency=medium

  * Merge with Debian Unstable. Remaining changes:
    - debian/control: Don't build-depend on python3-impacket and stunnel4 on
      i386 so we can drop it (and its dependencies) from the i386 partial port.
      It's only used for the tests, which do not block the build in any case.
    - d/{control,rules}: Do not use gnutls for the curl binary.
    - d/{control,rules}: Drop nghttp3 & ngtcp2 depdendencies of
      libcurl-gnutls to avoid component-mismatch.
    - d/rules: Use libssh2-dev as it is in main (LP: #2076865).

curl (8.11.1-1) unstable; urgency=medium

  [ Samuel Henrique ]
  * New upstream version 8.11.1
    - Fix CVE-2024-11053: netrc and redirect credential leak (closes: #1089682)
  * Update wcurl to 2024.12.08
  * New patches:
    - async_thread_avoid_closing_eventfd_twice: Fix file descriptor issue with eventfd
    - sectransp_free_certificate_on_error: Fix memory leak
  * Refresh patches:
    - ZZZgnutls-build
    - build-Divide-mit-krb5-gssapi-link-flags-between-LDFLAGS-a
  * d/p/11_omit-directories-from-config: Update patch
  * Drop merged patches:
    - cmdline_ech_md_formatting_cleanups
    - duphandle_also_init_netrc
    - libssh_when_using_IPv6_numerical_address_add_brackets
    - netrc_support_large_file_longer_lines_longer_tokens
    - setopt_fix_CURLOPT_HTTP_CONTENT_DECODING
  * d/p/Remove-curl-s-LDFLAGS-from-curl-config-static-libs: Remove patch, not needed anymore

  [ Carlos Henrique Lima Melara ]
  * d/t/upstream-tests-*: test gnutls backend against installed curl
  * d/t/control: install curl on upstream-tests-gnutls and remove on openssl

Date: Sat, 14 Dec 2024 03:39:34 -0600
Changed-By: Simon Quigley <tsimonq2 at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/curl/8.11.1-1ubuntu1
-------------- next part --------------
Format: 1.8
Date: Sat, 14 Dec 2024 03:39:34 -0600
Source: curl
Built-For-Profiles: noudeb
Architecture: source
Version: 8.11.1-1ubuntu1
Distribution: plucky
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Simon Quigley <tsimonq2 at ubuntu.com>
Closes: 1089682
Launchpad-Bugs-Fixed: 2076865
Changes:
 curl (8.11.1-1ubuntu1) plucky; urgency=medium
 .
   * Merge with Debian Unstable. Remaining changes:
     - debian/control: Don't build-depend on python3-impacket and stunnel4 on
       i386 so we can drop it (and its dependencies) from the i386 partial port.
       It's only used for the tests, which do not block the build in any case.
     - d/{control,rules}: Do not use gnutls for the curl binary.
     - d/{control,rules}: Drop nghttp3 & ngtcp2 depdendencies of
       libcurl-gnutls to avoid component-mismatch.
     - d/rules: Use libssh2-dev as it is in main (LP: #2076865).
 .
 curl (8.11.1-1) unstable; urgency=medium
 .
   [ Samuel Henrique ]
   * New upstream version 8.11.1
     - Fix CVE-2024-11053: netrc and redirect credential leak (closes: #1089682)
   * Update wcurl to 2024.12.08
   * New patches:
     - async_thread_avoid_closing_eventfd_twice: Fix file descriptor issue with eventfd
     - sectransp_free_certificate_on_error: Fix memory leak
   * Refresh patches:
     - ZZZgnutls-build
     - build-Divide-mit-krb5-gssapi-link-flags-between-LDFLAGS-a
   * d/p/11_omit-directories-from-config: Update patch
   * Drop merged patches:
     - cmdline_ech_md_formatting_cleanups
     - duphandle_also_init_netrc
     - libssh_when_using_IPv6_numerical_address_add_brackets
     - netrc_support_large_file_longer_lines_longer_tokens
     - setopt_fix_CURLOPT_HTTP_CONTENT_DECODING
   * d/p/Remove-curl-s-LDFLAGS-from-curl-config-static-libs: Remove patch, not needed anymore
 .
   [ Carlos Henrique Lima Melara ]
   * d/t/upstream-tests-*: test gnutls backend against installed curl
   * d/t/control: install curl on upstream-tests-gnutls and remove on openssl
Checksums-Sha1:
 ec99815d894aafa0b5651110a9f0d02a212d0726 3280 curl_8.11.1-1ubuntu1.dsc
 785a854854ea2f80754d6cfbf7e3074a3d04710c 4169067 curl_8.11.1.orig.tar.gz
 70366b9763c7be0134b75b3cfc1bf373007d7a21 484 curl_8.11.1.orig.tar.gz.asc
 4bfca64abbc1f93d952572af615073be6e9beb39 56044 curl_8.11.1-1ubuntu1.debian.tar.xz
 d460d59d618fa1bb12e2c9efaca258c9b227d6a3 9997 curl_8.11.1-1ubuntu1_source.buildinfo
Checksums-Sha256:
 dc631d2b61d042512836b79ab97aa77b3d6e474432d34815a34083d6930102b6 3280 curl_8.11.1-1ubuntu1.dsc
 a889ac9dbba3644271bd9d1302b5c22a088893719b72be3487bc3d401e5c4e80 4169067 curl_8.11.1.orig.tar.gz
 d6c44df0a8e6958ef8d38fceda44f219db666b8215da6b33dc7dda81fcfc696b 484 curl_8.11.1.orig.tar.gz.asc
 8a4fd140f2935eaebf2e8495aab2d51d220952a2797094c7f4f58469ce583791 56044 curl_8.11.1-1ubuntu1.debian.tar.xz
 4437e3e02672bde39edf1eb973a8003b47939e636f2f27e60423aecfa9ed799d 9997 curl_8.11.1-1ubuntu1_source.buildinfo
Files:
 e1b41d12bfd785e0bb9bf63da5753bf8 3280 web optional curl_8.11.1-1ubuntu1.dsc
 8eed752aeeb8ee54063b75baf95d3e14 4169067 web optional curl_8.11.1.orig.tar.gz
 6ef30ecafd1513f1d3cef9fd5f6508b9 484 web optional curl_8.11.1.orig.tar.gz.asc
 ee26f48937baec3863a98bbb74904738 56044 web optional curl_8.11.1-1ubuntu1.debian.tar.xz
 3e6d5bd68c64dfb94ec7d5300016a6ee 9997 web optional curl_8.11.1-1ubuntu1_source.buildinfo
Original-Maintainer: Debian Curl Maintainers <team+curl at tracker.debian.org>


More information about the plucky-changes mailing list