-
Wed Aug 08 2018 Kamil Dudka <kdudka@redhat.com> - 7.29.0-51
- require a new enough version of nss-pem to avoid regression in yum (#1610998)
-
Thu Jun 07 2018 Kamil Dudka <kdudka@redhat.com> - 7.29.0-50
- remove dead code, detected by Coverity Analysis
- remove unused variable, detected by GCC and Clang
-
Wed Jun 06 2018 Kamil Dudka <kdudka@redhat.com> - 7.29.0-49
- make curl --speed-limit work with TFTP (#1584750)
-
Wed May 30 2018 Kamil Dudka <kdudka@redhat.com> - 7.29.0-48
- fix RTSP bad headers buffer over-read (CVE-2018-1000301)
- fix FTP path trickery leads to NIL byte out of bounds write (CVE-2018-1000120)
- fix LDAP NULL pointer dereference (CVE-2018-1000121)
- fix RTSP RTP buffer over-read (CVE-2018-1000122)
- http: prevent custom Authorization headers in redirects (CVE-2018-1000007)
- doc: --tlsauthtype works only if built with TLS-SRP support (#1542256)
- update certificates in the test-suite because they expire soon (#1572723)
-
Fri Mar 02 2018 Kamil Dudka <kdudka@redhat.com> - 7.29.0-47
- make NSS deallocate PKCS #11 objects early enough (#1510247)
-
Mon Dec 11 2017 Kamil Dudka <kdudka@redhat.com> - 7.29.0-46
- reset authentication state when HTTP transfer is done (#1511523)
-
Mon Oct 23 2017 Kamil Dudka <kdudka@redhat.com> - 7.29.0-45
- fix buffer overflow while processing IMAP FETCH response (CVE-2017-1000257)
-
Thu Sep 14 2017 Kamil Dudka <kdudka@redhat.com> 7.29.0-44
- drop 0109-curl-7.29.0-crl-valgrind.patch no longer needed (#1427883)
-
Wed Sep 13 2017 Kamil Dudka <kdudka@redhat.com> 7.29.0-43
- curl --socks5-{basic,gssapi}: control socks5 auth (#1409208)
- nss: fix a memory leak when CURLOPT_CRLFILE is used (#1427883)
- nss: do not leak PKCS #11 slot while loading a key (#1444860)
- nss: fix a possible use-after-free in SelectClientCert() (#1473158)
-
Wed Mar 29 2017 Kamil Dudka <kdudka@redhat.com> 7.29.0-42
- fix use of uninitialized variable detected by Covscan