Описание
ELSA-2020-3916: curl security update (MODERATE)
[7.29.0-59.0.1]
- Fix TFTP small blocksize heap buffer overflow (https://curl.haxx.se/docs/CVE-2019-5482.html)[CVE-2019-5482][Orabug: 30568724]
- Security Fixes [OraBug: 28939992]
- CVE-2016-8615 cookie injection for other servers (https://curl.haxx.se/docs/CVE-2016-8615.html)
- CVE-2016-8616 case insensitive password comparison (https://curl.haxx.se/docs/CVE-2016-8616.html)
- CVE-2016-8617 OOB write via unchecked multiplication (https://curl.haxx.se/docs/CVE-2016-8617.html)
- CVE-2016-8618 double-free in curl_maprintf (https://curl.haxx.se/docs/CVE-2016-8618.html)
- CVE-2016-8619 double-free in krb5 code (https://curl.haxx.se/docs/CVE-2016-8619.html)
- CVE-2016-8621 curl_getdate read out of bounds (https://curl.haxx.se/docs/CVE-2016-8621.html)
- CVE-2016-8622 URL unescape heap overflow via integer truncation (https://curl.haxx.se/docs/CVE-2016-8622.html)
- CVE-2016-8623 Use-after-free via shared cookies (https://curl.haxx.se/docs/CVE-2016-8623.html)
- CVE-2016-8624 invalid URL parsing with # (https://curl.haxx.se/docs/CVE-2016-8624.html)
- Drop 1001-tftp-Alloc-maximum-blksize-and-use-default-unless-OA.patch
[7.29.0-59]
- http: free protocol-specific struct in setup_connection callback (#1836773)
[7.29.0-58]
- fix heap buffer overflow in function tftp_receive_packet() (CVE-2019-5482)
Обновленные пакеты
Oracle Linux 7
Oracle Linux aarch64
curl
7.29.0-59.0.1.el7
libcurl
7.29.0-59.0.1.el7
libcurl-devel
7.29.0-59.0.1.el7
Oracle Linux x86_64
curl
7.29.0-59.0.1.el7
libcurl
7.29.0-59.0.1.el7
libcurl-devel
7.29.0-59.0.1.el7
Связанные CVE
Связанные уязвимости
CVSS3: 9.8
ubuntu
почти 6 лет назад
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
CVSS3: 6.3
redhat
почти 6 лет назад
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
CVSS3: 9.8
nvd
почти 6 лет назад
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
CVSS3: 9.8
debian
почти 6 лет назад
Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7. ...