Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2015-2159

Опубликовано: 23 нояб. 2015
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2015-2159: curl security, bug fix, and enhancement update (MODERATE)

[7.29.0-25.0.1]

  • disable check to make build pass

[7.29.0-25]

  • fix spurious failure of test 1500 on ppc64le (#1218272)

[7.29.0-24]

  • use the default min/max TLS version provided by NSS (#1170339)
  • improve handling of timeouts and blocking direction to speed up FTP (#1218272)

[7.29.0-23]

  • require credentials to match for NTLM re-use (CVE-2015-3143)
  • close Negotiate connections when done (CVE-2015-3148)

[7.29.0-22]

  • reject CRLFs in URLs passed to proxy (CVE-2014-8150)

[7.29.0-21]

  • use only full matches for hosts used as IP address in cookies (CVE-2014-3613)
  • fix handling of CURLOPT_COPYPOSTFIELDS in curl_easy_duphandle (CVE-2014-3707)

[7.29.0-20]

  • eliminate unnecessary delay when resolving host from /etc/hosts (#1130239)
  • allow to enable/disable new AES cipher-suites (#1066065)
  • call PR_Cleanup() on curl tool exit if NSPR is used (#1071254)
  • implement non-blocking TLS handshake (#1091429)
  • fix limited connection re-use for unencrypted HTTP (#1101092)
  • disable libcurl-level downgrade to SSLv3 (#1154060)
  • include response headers added by proxy in CURLINFO_HEADER_SIZE (#1161182)
  • ignore CURLOPT_FORBID_REUSE during NTLM HTTP auth (#1166264)

Связанные уязвимости

oracle-oval
около 10 лет назад

ELSA-2015-1254: curl security, bug fix, and enhancement update (MODERATE)

ubuntu
почти 11 лет назад

cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.

redhat
почти 11 лет назад

cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.

nvd
почти 11 лет назад

cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.

debian
почти 11 лет назад

cURL and libcurl before 7.38.0 does not properly handle IP addresses i ...