- 
    Wed May 11 2022 Kamil Dudka <kdudka@redhat.com> - 7.76.1-14.el9_0.4
    
- fix too eager reuse of TLS and SSH connections (CVE-2022-27782)
   
  
  - 
    Mon May 02 2022 Kamil Dudka <kdudka@redhat.com> - 7.76.1-14.el9_0.3
    
- fix leak of SRP credentials in redirects (CVE-2022-27774)
   
  
  - 
    Fri Apr 29 2022 Kamil Dudka <kdudka@redhat.com> - 7.76.1-14.el9_0.2
    
- add missing tests to Makefile
   
  
  - 
    Thu Apr 28 2022 Kamil Dudka <kdudka@redhat.com> - 7.76.1-14.el9_0.1
    
- fix credential leak on redirect (CVE-2022-27774)
- fix auth/cookie leak on redirect (CVE-2022-27776)
- fix OAUTH2 bearer bypass in connection re-use (CVE-2022-22576)
   
  
  - 
    Tue Oct 26 2021 Kamil Dudka <kdudka@redhat.com> - 7.76.1-14
    
- re-disable HSTS in libcurl as an experimental feature (#2005874)
   
  
  - 
    Mon Oct 04 2021 Kamil Dudka <kdudka@redhat.com> - 7.76.1-13
    
- disable more protocols and features in libcurl-minimal (#2005874)
   
  
  - 
    Fri Sep 17 2021 Kamil Dudka <kdudka@redhat.com> - 7.76.1-12
    
- fix STARTTLS protocol injection via MITM (CVE-2021-22947)
- fix protocol downgrade required TLS bypass (CVE-2021-22946)
- fix use-after-free and double-free in MQTT sending (CVE-2021-22945)
   
  
  - 
    Mon Aug 09 2021 Mohan Boddu <mboddu@redhat.com> - 7.76.1-11
    
- Rebuilt for IMA sigs, glibc 2.34, aarch64 flags
  Related: rhbz#1991688
   
  
  - 
    Wed Jul 28 2021 Florian Weimer <fweimer@redhat.com> - 7.76.1-10
    
- Rebuild to pick up OpenSSL 3.0 Beta ABI (#1984097)
   
  
  - 
    Fri Jul 23 2021 Kamil Dudka <kdudka@redhat.com> - 7.76.1-9
    
- make explicit dependency on openssl work with alpha/beta builds of openssl