Hello community, here is the log from the commit of package curl for openSUSE:Factory checked in at 2014-09-12 15:25:04 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/curl (Old) and /work/SRC/openSUSE:Factory/.curl.new (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Package is "curl" Changes: -------- --- /work/SRC/openSUSE:Factory/curl/curl.changes 2014-09-01 16:59:07.000000000 +0200 +++ /work/SRC/openSUSE:Factory/.curl.new/curl.changes 2014-09-12 15:25:18.000000000 +0200 @@ -1,0 +2,25 @@ +Wed Sep 10 09:07:59 UTC 2014 - vcizek@suse.com + +- update to 7.38.0 + * fixes CVE-2014-3613 (bnc#894575) and CVE-2014-3620 (bnc#895991) + * cookie leaks with IP address as domain and TLDs respectively + Changes: + supports HTTP/2 draft-14 + CURLE_HTTP2 is a new error code + CURLAUTH_NEGOTIATE is a new auth define + CURL_VERSION_GSSAPI is a new capability bit + no longer use fbopenssl for anything + schannel: use CryptGenRandom for random numbers + axtls: define curlssl_random using axTLS's PRNG + cyassl: use RNG_GenerateBlock to generate a good random number + findprotocol: show unsupported protocol within quotes + version: detect and show LibreSSL + version: detect and show BoringSSL + imap/pop3/smtp: Kerberos (SASL GSSAPI) authentication via Windows SSPI + http2: requires nghttp2 0.6.0 or later + Bugfixes: + SECURITY ADVISORY: cookie leak with IP address as domain + SECURITY ADVISORY: cookie leak for TLDs + And many other fixes + +------------------------------------------------------------------- Old: ---- curl-7.37.1.tar.lzma curl-7.37.1.tar.lzma.asc New: ---- curl-7.38.0.tar.lzma curl-7.38.0.tar.lzma.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ curl.spec ++++++ --- /var/tmp/diff_new_pack.fieuSN/_old 2014-09-12 15:25:19.000000000 +0200 +++ /var/tmp/diff_new_pack.fieuSN/_new 2014-09-12 15:25:19.000000000 +0200 @@ -21,7 +21,7 @@ %bcond_without testsuite Name: curl -Version: 7.37.1 +Version: 7.38.0 Release: 0 Summary: A Tool for Transferring Data from URLs License: BSD-3-Clause and MIT -- To unsubscribe, e-mail: opensuse-commit+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-commit+help@opensuse.org