Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2019-2181

Опубликовано: 13 авг. 2019
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2019-2181: curl security and bug fix update (LOW)

[7.29.0-54.0.1]

[7.29.0-54]

  • make 'curl --tlsv1' backward compatible (#1672639)

[7.29.0-53]

  • backport the --tls-max option of curl and TLS 1.3 ciphers (#1672639)

[7.29.0-52]

  • prevent curl --rate-limit from hanging on file URLs (#1281969)
  • fix NTLM password overflow via integer overflow (CVE-2018-14618)
  • fix bad arithmetic when outputting warnings to stderr (CVE-2018-16842)
  • backport options to force TLS 1.3 in curl and libcurl (#1672639)
  • prevent curl --rate-limit from crashing on https URLs (#1683292)

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

curl

7.29.0-54.0.1.el7

libcurl

7.29.0-54.0.1.el7

libcurl-devel

7.29.0-54.0.1.el7

Oracle Linux x86_64

curl

7.29.0-54.0.1.el7

libcurl

7.29.0-54.0.1.el7

libcurl-devel

7.29.0-54.0.1.el7

Связанные CVE

Связанные уязвимости

CVSS3: 4.4
ubuntu
больше 7 лет назад

Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buffer over-read in the tool_msgs.c:voutf() function that may result in information exposure and denial of service.

CVSS3: 3.6
redhat
больше 7 лет назад

Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buffer over-read in the tool_msgs.c:voutf() function that may result in information exposure and denial of service.

CVSS3: 4.4
nvd
больше 7 лет назад

Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buffer over-read in the tool_msgs.c:voutf() function that may result in information exposure and denial of service.

CVSS3: 4.4
debian
больше 7 лет назад

Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buf ...

CVSS3: 9.1
github
больше 3 лет назад

Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buffer over-read in the tool_msgs.c:voutf() function that may result in information exposure and denial of service.