Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2018:0769-1

Опубликовано: 22 мар. 2018
Источник: suse-cvrf

Описание

Security update for curl

This update for curl fixes the following issues:

Following security issues were fixed:

  • CVE-2018-1000120: A buffer overflow exists in the FTP URL handling that allowed an attacker to cause a denial of service or possible code execution (bsc#1084521).
  • CVE-2018-1000121: A NULL pointer dereference exists in the LDAP code that allowed an attacker to cause a denial of service (bsc#1084524).
  • CVE-2018-1000122: A buffer over-read exists in the RTSP+RTP handling code that allowed an attacker to cause a denial of service or information leakage (bsc#1084532).

Список пакетов

SUSE Linux Enterprise Desktop 12 SP2
curl-7.37.0-37.17.1
libcurl4-7.37.0-37.17.1
libcurl4-32bit-7.37.0-37.17.1
SUSE Linux Enterprise Desktop 12 SP3
curl-7.37.0-37.17.1
libcurl4-7.37.0-37.17.1
libcurl4-32bit-7.37.0-37.17.1
SUSE Linux Enterprise Server 12 SP2
curl-7.37.0-37.17.1
libcurl4-7.37.0-37.17.1
libcurl4-32bit-7.37.0-37.17.1
SUSE Linux Enterprise Server 12 SP3
curl-7.37.0-37.17.1
libcurl4-7.37.0-37.17.1
libcurl4-32bit-7.37.0-37.17.1
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
curl-7.37.0-37.17.1
libcurl4-7.37.0-37.17.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
curl-7.37.0-37.17.1
libcurl4-7.37.0-37.17.1
libcurl4-32bit-7.37.0-37.17.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
curl-7.37.0-37.17.1
libcurl4-7.37.0-37.17.1
libcurl4-32bit-7.37.0-37.17.1
SUSE Linux Enterprise Software Development Kit 12 SP2
libcurl-devel-7.37.0-37.17.1
SUSE Linux Enterprise Software Development Kit 12 SP3
libcurl-devel-7.37.0-37.17.1

Описание

A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or worse.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP2:curl-7.37.0-37.17.1
SUSE Linux Enterprise Desktop 12 SP2:libcurl4-32bit-7.37.0-37.17.1
SUSE Linux Enterprise Desktop 12 SP2:libcurl4-7.37.0-37.17.1
SUSE Linux Enterprise Desktop 12 SP3:curl-7.37.0-37.17.1

Ссылки

Описание

A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that allows an attacker to cause a denial of service


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP2:curl-7.37.0-37.17.1
SUSE Linux Enterprise Desktop 12 SP2:libcurl4-32bit-7.37.0-37.17.1
SUSE Linux Enterprise Desktop 12 SP2:libcurl4-7.37.0-37.17.1
SUSE Linux Enterprise Desktop 12 SP3:curl-7.37.0-37.17.1

Ссылки

Описание

A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of service or information leakage


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP2:curl-7.37.0-37.17.1
SUSE Linux Enterprise Desktop 12 SP2:libcurl4-32bit-7.37.0-37.17.1
SUSE Linux Enterprise Desktop 12 SP2:libcurl4-7.37.0-37.17.1
SUSE Linux Enterprise Desktop 12 SP3:curl-7.37.0-37.17.1

Ссылки
Уязвимость SUSE-SU-2018:0769-1