Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2017-0847

Опубликовано: 29 мар. 2017
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2017-0847: curl security update (MODERATE)

[7.19.7-53]

  • treat Negotiate authentication as connection-oriented (CVE-2017-2628)

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

curl

7.19.7-53.el6_9

libcurl

7.19.7-53.el6_9

libcurl-devel

7.19.7-53.el6_9

Oracle Linux i686

curl

7.19.7-53.el6_9

libcurl

7.19.7-53.el6_9

libcurl-devel

7.19.7-53.el6_9

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not reflect the fact that the HAVE_GSSAPI define was meanwhile substituted by USE_HTTP_NEGOTIATE. This issue was introduced in RHEL 6.7 and affects RHEL 6 curl only.

CVSS3: 4.8
redhat
больше 8 лет назад

curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not reflect the fact that the HAVE_GSSAPI define was meanwhile substituted by USE_HTTP_NEGOTIATE. This issue was introduced in RHEL 6.7 and affects RHEL 6 curl only.

CVSS3: 9.8
nvd
больше 7 лет назад

curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not reflect the fact that the HAVE_GSSAPI define was meanwhile substituted by USE_HTTP_NEGOTIATE. This issue was introduced in RHEL 6.7 and affects RHEL 6 curl only.

CVSS3: 9.8
debian
больше 7 лет назад

curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-5 ...

CVSS3: 9.8
github
больше 3 лет назад

curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not reflect the fact that the HAVE_GSSAPI define was meanwhile substituted by USE_HTTP_NEGOTIATE. This issue was introduced in RHEL 6.7 and affects RHEL 6 curl only.