Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-4599

Опубликовано: 10 нояб. 2020
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2020-4599: curl security and bug fix update (MODERATE)

[7.61.1-14]

  • avoid overwriting a local file with -J (CVE-2020-8177)

[7.61.1-13]

  • load built-in openssl engines (#1854369)

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

curl

7.61.1-14.el8

libcurl

7.61.1-14.el8

libcurl-devel

7.61.1-14.el8

libcurl-minimal

7.61.1-14.el8

Oracle Linux x86_64

curl

7.61.1-14.el8

libcurl

7.61.1-14.el8

libcurl-devel

7.61.1-14.el8

libcurl-minimal

7.61.1-14.el8

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 5 лет назад

curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.

CVSS3: 5.4
redhat
больше 5 лет назад

curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.

CVSS3: 7.8
nvd
около 5 лет назад

curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.

CVSS3: 7.8
msrc
около 5 лет назад

curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.

CVSS3: 7.8
debian
около 5 лет назад

curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of na ...