Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2015:0962-1

Опубликовано: 15 апр. 2014
Источник: suse-cvrf

Описание

Security update for curl

This curl update fixes the following security issues:

* bnc#868627: wrong re-use of connections (CVE-2014-0138). * bnc#868629: IP address wildcard certificate validation (CVE-2014-0139). * bnc#870444: --insecure option inappropriately enforcing security safeguard.

Security Issue references:

* CVE-2014-0138 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0138> * CVE-2014-0139 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0139>

Список пакетов

SUSE Linux Enterprise Desktop 11 SP3
curl-7.19.7-1.38.1
libcurl4-7.19.7-1.38.1
libcurl4-32bit-7.19.7-1.38.1
SUSE Linux Enterprise Server 11 SP3
curl-7.19.7-1.38.1
libcurl4-7.19.7-1.38.1
libcurl4-32bit-7.19.7-1.38.1
libcurl4-x86-7.19.7-1.38.1
SUSE Linux Enterprise Server 11 SP3-TERADATA
curl-7.19.7-1.38.1
libcurl4-7.19.7-1.38.1
libcurl4-32bit-7.19.7-1.38.1
libcurl4-x86-7.19.7-1.38.1
SUSE Linux Enterprise Server for SAP Applications 11 SP3
curl-7.19.7-1.38.1
libcurl4-7.19.7-1.38.1
libcurl4-32bit-7.19.7-1.38.1
libcurl4-x86-7.19.7-1.38.1
SUSE Linux Enterprise Software Development Kit 11 SP3
libcurl-devel-7.19.7-1.38.1

Описание

Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string ending in a "%" (percent) character.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:curl-7.19.7-1.38.1
SUSE Linux Enterprise Desktop 11 SP3:libcurl4-32bit-7.19.7-1.38.1
SUSE Linux Enterprise Desktop 11 SP3:libcurl4-7.19.7-1.38.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:curl-7.19.7-1.38.1

Ссылки

Описание

cURL and libcurl 7.18.0 through 7.32.0, when built with OpenSSL, disables the certificate CN and SAN name field verification (CURLOPT_SSL_VERIFYHOST) when the digital signature verification (CURLOPT_SSL_VERIFYPEER) is disabled, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:curl-7.19.7-1.38.1
SUSE Linux Enterprise Desktop 11 SP3:libcurl4-32bit-7.19.7-1.38.1
SUSE Linux Enterprise Desktop 11 SP3:libcurl4-7.19.7-1.38.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:curl-7.19.7-1.38.1

Ссылки

Описание

cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:curl-7.19.7-1.38.1
SUSE Linux Enterprise Desktop 11 SP3:libcurl4-32bit-7.19.7-1.38.1
SUSE Linux Enterprise Desktop 11 SP3:libcurl4-7.19.7-1.38.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:curl-7.19.7-1.38.1

Ссылки

Описание

The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:curl-7.19.7-1.38.1
SUSE Linux Enterprise Desktop 11 SP3:libcurl4-32bit-7.19.7-1.38.1
SUSE Linux Enterprise Desktop 11 SP3:libcurl4-7.19.7-1.38.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:curl-7.19.7-1.38.1

Ссылки

Описание

cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:curl-7.19.7-1.38.1
SUSE Linux Enterprise Desktop 11 SP3:libcurl4-32bit-7.19.7-1.38.1
SUSE Linux Enterprise Desktop 11 SP3:libcurl4-7.19.7-1.38.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:curl-7.19.7-1.38.1

Ссылки

Описание

cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:curl-7.19.7-1.38.1
SUSE Linux Enterprise Desktop 11 SP3:libcurl4-32bit-7.19.7-1.38.1
SUSE Linux Enterprise Desktop 11 SP3:libcurl4-7.19.7-1.38.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:curl-7.19.7-1.38.1

Ссылки

Описание

cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:curl-7.19.7-1.38.1
SUSE Linux Enterprise Desktop 11 SP3:libcurl4-32bit-7.19.7-1.38.1
SUSE Linux Enterprise Desktop 11 SP3:libcurl4-7.19.7-1.38.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:curl-7.19.7-1.38.1

Ссылки

Описание

The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:curl-7.19.7-1.38.1
SUSE Linux Enterprise Desktop 11 SP3:libcurl4-32bit-7.19.7-1.38.1
SUSE Linux Enterprise Desktop 11 SP3:libcurl4-7.19.7-1.38.1
SUSE Linux Enterprise Server 11 SP3-TERADATA:curl-7.19.7-1.38.1

Ссылки
Уязвимость SUSE-SU-2015:0962-1