Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-1020

Опубликовано: 06 апр. 2020
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2020-1020: curl security and bug fix update (LOW)

[7.29.0-57.0.1]

[7.29.0-57]

  • allow curl to POST from a char device (#1769307)

[7.29.0-56]

  • fix auth failure with duplicated WWW-Authenticate header (#1754736)

[7.29.0-55]

  • fix TFTP receive buffer overflow (CVE-2019-5436)

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

curl

7.29.0-57.0.1.el7

libcurl

7.29.0-57.0.1.el7

libcurl-devel

7.29.0-57.0.1.el7

Oracle Linux x86_64

curl

7.29.0-57.0.1.el7

libcurl

7.29.0-57.0.1.el7

libcurl-devel

7.29.0-57.0.1.el7

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 6 лет назад

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

CVSS3: 7
redhat
около 6 лет назад

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

CVSS3: 7.8
nvd
около 6 лет назад

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

CVSS3: 7.8
debian
около 6 лет назад

A heap buffer overflow in the TFTP receiving code allows for DoS or ar ...

suse-cvrf
около 6 лет назад

Security update for curl