Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-5002

Опубликовано: 12 нояб. 2020
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2020-5002: curl security update (MODERATE)

[7.29.0-59.0.1.1]

[7.29.0-59.el7_9.1]

  • avoid overwriting a local file with -J (CVE-2020-8177)

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

curl

7.29.0-59.0.1.el7_9.1

libcurl

7.29.0-59.0.1.el7_9.1

libcurl-devel

7.29.0-59.0.1.el7_9.1

Oracle Linux x86_64

curl

7.29.0-59.0.1.el7_9.1

libcurl

7.29.0-59.0.1.el7_9.1

libcurl-devel

7.29.0-59.0.1.el7_9.1

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 5 лет назад

curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.

CVSS3: 5.4
redhat
больше 5 лет назад

curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.

CVSS3: 7.8
nvd
около 5 лет назад

curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.

CVSS3: 7.8
msrc
около 5 лет назад

curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.

CVSS3: 7.8
debian
около 5 лет назад

curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of na ...