Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2021:1763-1

Опубликовано: 26 мая 2021
Источник: suse-cvrf

Описание

Security update for curl

This update for curl fixes the following issues:

  • CVE-2021-22898: Fixed curl TELNET stack contents disclosure (bsc#1186114).
  • Allow partial chain verification [jsc#SLE-17956]
    • Have intermediate certificates in the trust store be treated as trust-anchors, in the same way as self-signed root CA certificates are. This allows users to verify servers using the intermediate cert only, instead of needing the whole chain.
    • Set FLAG_TRUSTED_FIRST unconditionally.
    • Do not check partial chains with CRL check.

Список пакетов

Container suse/ltss/sle12.5/sles12sp5:latest
libcurl4-7.60.0-11.18.1
Container suse/sles12sp5:latest
libcurl4-7.60.0-11.18.1
Image SLES12-SP5-Azure-BYOS
curl-7.60.0-11.18.1
libcurl4-7.60.0-11.18.1
Image SLES12-SP5-Azure-Basic-On-Demand
curl-7.60.0-11.18.1
libcurl4-7.60.0-11.18.1
Image SLES12-SP5-Azure-HPC-BYOS
curl-7.60.0-11.18.1
libcurl4-7.60.0-11.18.1
Image SLES12-SP5-Azure-HPC-On-Demand
curl-7.60.0-11.18.1
libcurl4-7.60.0-11.18.1
Image SLES12-SP5-Azure-SAP-BYOS
curl-7.60.0-11.18.1
libcurl4-7.60.0-11.18.1
Image SLES12-SP5-Azure-SAP-On-Demand
curl-7.60.0-11.18.1
libcurl4-7.60.0-11.18.1
Image SLES12-SP5-Azure-Standard-On-Demand
curl-7.60.0-11.18.1
libcurl4-7.60.0-11.18.1
Image SLES12-SP5-EC2-BYOS
curl-7.60.0-11.18.1
libcurl4-7.60.0-11.18.1
Image SLES12-SP5-EC2-ECS-On-Demand
libcurl4-7.60.0-11.18.1
Image SLES12-SP5-EC2-On-Demand
curl-7.60.0-11.18.1
libcurl4-7.60.0-11.18.1
Image SLES12-SP5-EC2-SAP-BYOS
curl-7.60.0-11.18.1
libcurl4-7.60.0-11.18.1
Image SLES12-SP5-EC2-SAP-On-Demand
curl-7.60.0-11.18.1
libcurl4-7.60.0-11.18.1
Image SLES12-SP5-GCE-BYOS
curl-7.60.0-11.18.1
libcurl4-7.60.0-11.18.1
Image SLES12-SP5-GCE-On-Demand
curl-7.60.0-11.18.1
libcurl4-7.60.0-11.18.1
Image SLES12-SP5-GCE-SAP-BYOS
curl-7.60.0-11.18.1
libcurl4-7.60.0-11.18.1
Image SLES12-SP5-GCE-SAP-On-Demand
curl-7.60.0-11.18.1
libcurl4-7.60.0-11.18.1
Image SLES12-SP5-OCI-BYOS-BYOS
curl-7.60.0-11.18.1
libcurl4-7.60.0-11.18.1
Image SLES12-SP5-OCI-BYOS-SAP-BYOS
curl-7.60.0-11.18.1
libcurl4-7.60.0-11.18.1
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
curl-7.60.0-11.18.1
libcurl4-7.60.0-11.18.1
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
curl-7.60.0-11.18.1
libcurl4-7.60.0-11.18.1
SUSE Linux Enterprise Server 12 SP5
curl-7.60.0-11.18.1
libcurl4-7.60.0-11.18.1
libcurl4-32bit-7.60.0-11.18.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
curl-7.60.0-11.18.1
libcurl4-7.60.0-11.18.1
libcurl4-32bit-7.60.0-11.18.1
SUSE Linux Enterprise Software Development Kit 12 SP5
libcurl-devel-7.60.0-11.18.1

Описание

curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the server, resulting in potentially revealing sensitive internal information to the server using a clear-text network protocol.


Затронутые продукты
Container suse/ltss/sle12.5/sles12sp5:latest:libcurl4-7.60.0-11.18.1
Container suse/sles12sp5:latest:libcurl4-7.60.0-11.18.1
Image SLES12-SP5-Azure-BYOS:curl-7.60.0-11.18.1
Image SLES12-SP5-Azure-BYOS:libcurl4-7.60.0-11.18.1

Ссылки