﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
6443	curl-7.42.1	Fernando de Oliveira	Fernando de Oliveira	"This release comes bundled another security advisory:

'''CVE-2015-3153''': sensitive HTTP server headers also sent to proxies:

[http://curl.haxx.se/docs/adv_20150429.html]

[http://curl.haxx.se/download/curl-7.42.1.tar.lzma]

[http://curl.haxx.se/download/curl-7.42.1.tar.lzma.asc]

[http://curl.haxx.se/changes.html#7_42_1]

{{{
 Fixed in 7.42.1 - April 29 2015

Bugfixes:

   • CURLOPT_HEADEROPT: default to separate
   • dist: include {src,lib}/checksrc.whitelist
   • connectionexists: fix build without NTLM
   • docs: distribute the CURLOPT_PINNEDPUBLICKEY man page, too
   • curl -z: do not write empty file on unmet condition
   • openssl: fix serial number output
   • curl_easy_getinfo.3: document 'internals' in CURLINFO_TLS_SESSION
   • sws: init http2 state properly
   • curl.1: fix typo
}}}
"	enhancement	closed	high	7.8	BOOK	SVN	medium	fixed		
