Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2016-2575

Опубликовано: 09 нояб. 2016
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2016-2575: curl security, bug fix, and enhancement update (MODERATE)

[7.29.0-35]

  • fix incorrect use of a previously loaded certificate from file (related to CVE-2016-5420)

[7.29.0-34]

  • acknowledge the --no-sessionid/CURLOPT_SSL_SESSIONID_CACHE option (required by the fix for CVE-2016-5419)

[7.29.0-33]

  • fix re-using connections with wrong client cert (CVE-2016-5420)
  • fix TLS session resumption client cert bypass (CVE-2016-5419)

[7.29.0-32]

  • configure: improve detection of GCC's -fvisibility= flag

[7.29.0-31]

  • prevent curl_multi_wait() from missing an event (#1347904)

[7.29.0-30]

  • curl.1: --disable-{eprt,epsv} are ignored for IPv6 hosts (#1305974)

[7.29.0-29]

  • SSH: make CURLOPT_SSH_PUBLIC_KEYFILE treat '' as NULL (#1275769)

[7.29.0-28]

  • prevent NSS from incorrectly re-using a session (#1269855)
  • call PR_Cleanup() in the upstream test-suite if NSPR is used (#1243324)
  • disable unreliable upstream test-case 2032 (#1241168)

[7.29.0-27]

  • SSH: do not require public key file for user authentication (#1275769)

[7.29.0-26]

  • implement 'curl --unix-socket' and CURLOPT_UNIX_SOCKET_PATH (#1263318)
  • improve parsing of URL-encoded user name and password (#1260178)
  • prevent test46 from failing due to expired cookie (#1258834)

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

curl

7.29.0-35.el7

libcurl

7.29.0-35.el7

libcurl-devel

7.29.0-35.el7

Связанные уязвимости

suse-cvrf
почти 9 лет назад

Security update for curl

suse-cvrf
почти 9 лет назад

Security update for curl

suse-cvrf
почти 9 лет назад

Security update for curl

CVSS3: 7.5
ubuntu
почти 9 лет назад

curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.

CVSS3: 4.2
redhat
около 9 лет назад

curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.