Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:4597-1

Опубликовано: 21 дек. 2022
Источник: suse-cvrf

Описание

Security update for curl

This update for curl fixes the following issues:

  • CVE-2022-43552: HTTP Proxy deny use-after-free (bsc#1206309).
  • CVE-2022-43551: Fixed HSTS bypass via IDN (bsc#1206308).

Список пакетов

Container bci/bci-init:15.4
libcurl4-7.79.1-150400.5.12.1
Container bci/dotnet-aspnet:3.1
libcurl4-7.79.1-150400.5.12.1
Container bci/dotnet-aspnet:5.0
libcurl4-7.79.1-150400.5.12.1
Container bci/dotnet-aspnet:6.0
libcurl4-7.79.1-150400.5.12.1
Container bci/dotnet-aspnet:latest
libcurl4-7.79.1-150400.5.12.1
Container bci/dotnet-runtime:3.1
libcurl4-7.79.1-150400.5.12.1
Container bci/dotnet-runtime:5.0
libcurl4-7.79.1-150400.5.12.1
Container bci/dotnet-runtime:6.0
libcurl4-7.79.1-150400.5.12.1
Container bci/dotnet-runtime:latest
libcurl4-7.79.1-150400.5.12.1
Container bci/dotnet-sdk:3.1
libcurl4-7.79.1-150400.5.12.1
Container bci/dotnet-sdk:5.0
libcurl4-7.79.1-150400.5.12.1
Container bci/dotnet-sdk:6.0
libcurl4-7.79.1-150400.5.12.1
Container bci/dotnet-sdk:latest
libcurl4-7.79.1-150400.5.12.1
Container bci/golang:1.16
libcurl4-7.79.1-150400.5.12.1
Container bci/golang:1.17
libcurl4-7.79.1-150400.5.12.1
Container bci/golang:1.18
libcurl4-7.79.1-150400.5.12.1
Container bci/golang:1.19
libcurl4-7.79.1-150400.5.12.1
Container bci/golang:1.20-openssl
libcurl4-7.79.1-150400.5.12.1
Container bci/golang:1.21
libcurl4-7.79.1-150400.5.12.1
Container bci/golang:latest
libcurl4-7.79.1-150400.5.12.1
Container bci/node:14
libcurl4-7.79.1-150400.5.12.1
Container bci/node:16
libcurl4-7.79.1-150400.5.12.1
Container bci/node:18
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container bci/nodejs:latest
libcurl4-7.79.1-150400.5.12.1
Container bci/openjdk-devel:11
libcurl4-7.79.1-150400.5.12.1
Container bci/openjdk-devel:latest
libcurl4-7.79.1-150400.5.12.1
Container bci/openjdk:11
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container bci/openjdk:17
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container bci/openjdk:latest
libcurl4-7.79.1-150400.5.12.1
Container bci/php-apache:8
libcurl4-7.79.1-150400.5.12.1
Container bci/php-apache:latest
libcurl4-7.79.1-150400.5.12.1
Container bci/php-fpm:8
libcurl4-7.79.1-150400.5.12.1
Container bci/php-fpm:latest
libcurl4-7.79.1-150400.5.12.1
Container bci/php:8
libcurl4-7.79.1-150400.5.12.1
Container bci/php:latest
libcurl4-7.79.1-150400.5.12.1
Container bci/python:3
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container bci/python:latest
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container bci/ruby:latest
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container bci/rust:1.64
libcurl4-7.79.1-150400.5.12.1
Container bci/rust:1.65
libcurl4-7.79.1-150400.5.12.1
Container bci/rust:1.66
libcurl4-7.79.1-150400.5.12.1
Container bci/rust:1.67
libcurl4-7.79.1-150400.5.12.1
Container bci/rust:1.68
libcurl4-7.79.1-150400.5.12.1
Container bci/rust:1.77
libcurl4-7.79.1-150400.5.12.1
Container bci/rust:latest
libcurl4-7.79.1-150400.5.12.1
Container rancher/elemental-builder-image/5.3:latest
libcurl4-7.79.1-150400.5.12.1
Container rancher/elemental-operator/5.3:latest
libcurl4-7.79.1-150400.5.12.1
Container rancher/elemental-operator:latest
libcurl4-7.79.1-150400.5.12.1
Container rancher/elemental-teal-iso/5.3:latest
libcurl4-7.79.1-150400.5.12.1
Container rancher/elemental-teal-iso/5.4:latest
libcurl4-7.79.1-150400.5.12.1
Container rancher/elemental-teal-rt/5.3:latest
libcurl4-7.79.1-150400.5.12.1
Container rancher/elemental-teal-rt/5.4:latest
libcurl4-7.79.1-150400.5.12.1
Container rancher/elemental-teal/5.3:latest
libcurl4-7.79.1-150400.5.12.1
Container rancher/elemental-teal/5.4:latest
libcurl4-7.79.1-150400.5.12.1
Container rancher/seedimage-builder/5.3:latest
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container rancher/seedimage-builder:latest
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container suse/389-ds:latest
libcurl4-7.79.1-150400.5.12.1
Container suse/git:latest
libcurl4-7.79.1-150400.5.12.1
Container suse/hpc/warewulf4-x86_64/sle-hpc-node:latest
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container suse/ltss/sle15.4/bci-base:latest
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container suse/ltss/sle15.5/sle15:latest
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container suse/manager/4.3/proxy-httpd:latest
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container suse/manager/4.3/proxy-salt-broker:latest
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container suse/pcp:5
libcurl4-7.79.1-150400.5.12.1
Container suse/postgres:12
libcurl4-7.79.1-150400.5.12.1
Container suse/postgres:13
libcurl4-7.79.1-150400.5.12.1
Container suse/postgres:14
libcurl4-7.79.1-150400.5.12.1
Container suse/postgres:latest
libcurl4-7.79.1-150400.5.12.1
Container suse/rmt-mariadb-client:latest
libcurl4-7.79.1-150400.5.12.1
Container suse/rmt-mariadb:latest
libcurl4-7.79.1-150400.5.12.1
Container suse/rmt-nginx:latest
libcurl4-7.79.1-150400.5.12.1
Container suse/rmt-server:latest
libcurl4-7.79.1-150400.5.12.1
Container suse/sle-micro-rancher/5.3:latest
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container suse/sle-micro-rancher/5.4:latest
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container suse/sle-micro/5.3/toolbox:latest
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container suse/sle-micro/5.4/toolbox:latest
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container suse/sle-micro/5.5/toolbox:latest
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container suse/sle-micro/5.5:latest
libcurl4-7.79.1-150400.5.12.1
Container suse/sle-micro/base-5.5:latest
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container suse/sle-micro/kvm-5.5:latest
libcurl4-7.79.1-150400.5.12.1
Container suse/sle-micro/rt-5.5:latest
libcurl4-7.79.1-150400.5.12.1
Container suse/sle15:15.4
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container suse/sle15:15.5
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container suse/sles/15.5/cdi-apiserver:1.55.0
libcurl4-7.79.1-150400.5.12.1
Container suse/sles/15.5/cdi-cloner:1.55.0
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container suse/sles/15.5/cdi-controller:1.55.0
libcurl4-7.79.1-150400.5.12.1
Container suse/sles/15.5/cdi-importer:1.55.0
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container suse/sles/15.5/cdi-operator:1.55.0
libcurl4-7.79.1-150400.5.12.1
Container suse/sles/15.5/cdi-uploadproxy:1.55.0
libcurl4-7.79.1-150400.5.12.1
Container suse/sles/15.5/cdi-uploadserver:1.55.0
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container suse/sles/15.5/libguestfs-tools:0.58.0
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container suse/sles/15.5/virt-api:0.58.0
libcurl4-7.79.1-150400.5.12.1
Container suse/sles/15.5/virt-controller:0.58.0
libcurl4-7.79.1-150400.5.12.1
Container suse/sles/15.5/virt-exportproxy:0.58.0
libcurl4-7.79.1-150400.5.12.1
Container suse/sles/15.5/virt-exportserver:0.58.0
libcurl4-7.79.1-150400.5.12.1
Container suse/sles/15.5/virt-handler:0.58.0
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container suse/sles/15.5/virt-launcher:0.58.0
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Container suse/sles/15.5/virt-operator:0.58.0
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Azure-Basic
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Azure-Standard
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-BYOS
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-BYOS-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-BYOS-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-BYOS-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-CHOST-BYOS
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-CHOST-BYOS-Aliyun
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-CHOST-BYOS-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-CHOST-BYOS-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-CHOST-BYOS-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-CHOST-BYOS-SAP-CCloud
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-EC2-ECS-HVM
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-HPC
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-HPC-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-HPC-BYOS
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-HPC-BYOS-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-HPC-BYOS-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-HPC-BYOS-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-HPC-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-HPC-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Hardened-BYOS
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Hardened-BYOS-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Hardened-BYOS-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Hardened-BYOS-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Manager-Proxy-4-3-BYOS
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Manager-Proxy-4-3-BYOS-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Manager-Proxy-4-3-BYOS-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Manager-Proxy-4-3-BYOS-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Manager-Server-4-3
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Manager-Server-4-3-Azure-llc
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Manager-Server-4-3-Azure-ltd
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Manager-Server-4-3-BYOS
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Manager-Server-4-3-EC2-llc
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Manager-Server-4-3-EC2-ltd
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Micro-5-3
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Micro-5-3-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Micro-5-3-BYOS
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Micro-5-3-BYOS-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Micro-5-3-BYOS-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Micro-5-3-BYOS-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Micro-5-3-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Micro-5-3-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Micro-5-4
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Micro-5-4-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Micro-5-4-BYOS
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Micro-5-4-BYOS-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Micro-5-4-BYOS-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Micro-5-4-BYOS-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Micro-5-4-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-Micro-5-4-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-SAP
curl-7.79.1-150400.5.12.1
libcurl-devel-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
libcurl4-32bit-7.79.1-150400.5.12.1
Image SLES15-SP4-SAP-Azure
curl-7.79.1-150400.5.12.1
libcurl-devel-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
libcurl4-32bit-7.79.1-150400.5.12.1
Image SLES15-SP4-SAP-Azure-LI-BYOS
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-SAP-Azure-LI-BYOS-Production
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-SAP-Azure-VLI-BYOS
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-SAP-BYOS
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-SAP-BYOS-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-SAP-BYOS-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-SAP-BYOS-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-SAP-EC2
curl-7.79.1-150400.5.12.1
libcurl-devel-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
libcurl4-32bit-7.79.1-150400.5.12.1
Image SLES15-SP4-SAP-GCE
curl-7.79.1-150400.5.12.1
libcurl-devel-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
libcurl4-32bit-7.79.1-150400.5.12.1
Image SLES15-SP4-SAP-Hardened
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-SAP-Hardened-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-SAP-Hardened-BYOS
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-SAP-Hardened-BYOS-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-SAP-Hardened-BYOS-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-SAP-Hardened-BYOS-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-SAP-Hardened-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-SAP-Hardened-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-SAPCAL
curl-7.79.1-150400.5.12.1
libcurl-devel-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
libcurl4-32bit-7.79.1-150400.5.12.1
Image SLES15-SP4-SAPCAL-Azure
curl-7.79.1-150400.5.12.1
libcurl-devel-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
libcurl4-32bit-7.79.1-150400.5.12.1
Image SLES15-SP4-SAPCAL-EC2
curl-7.79.1-150400.5.12.1
libcurl-devel-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
libcurl4-32bit-7.79.1-150400.5.12.1
Image SLES15-SP4-SAPCAL-GCE
curl-7.79.1-150400.5.12.1
libcurl-devel-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
libcurl4-32bit-7.79.1-150400.5.12.1
Image SLES15-SP4-SUSE-Rancher-Setup-BYOS
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP4-SUSE-Rancher-Setup-BYOS-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Azure-3P
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Azure-Basic
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Azure-Standard
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-BYOS-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-BYOS-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-BYOS-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-CHOST-BYOS-Aliyun
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-CHOST-BYOS-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-CHOST-BYOS-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-CHOST-BYOS-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-CHOST-BYOS-GDC
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-CHOST-BYOS-SAP-CCloud
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-EC2-ECS-HVM
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-HPC-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-HPC-BYOS-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-HPC-BYOS-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-HPC-BYOS-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-HPC-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-HPC-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Hardened-BYOS-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Hardened-BYOS-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Hardened-BYOS-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Manager-Proxy-5-0-BYOS
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Manager-Proxy-5-0-BYOS-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Manager-Proxy-5-0-BYOS-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Manager-Proxy-5-0-BYOS-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Manager-Server-5-0
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Manager-Server-5-0-Azure-llc
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Manager-Server-5-0-Azure-ltd
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Manager-Server-5-0-BYOS
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Manager-Server-5-0-BYOS-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Manager-Server-5-0-BYOS-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Manager-Server-5-0-BYOS-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Manager-Server-5-0-EC2-llc
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Manager-Server-5-0-EC2-ltd
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Micro-5-5
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Micro-5-5-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Micro-5-5-BYOS
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Micro-5-5-BYOS-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Micro-5-5-BYOS-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Micro-5-5-BYOS-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Micro-5-5-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-Micro-5-5-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-SAP-Azure
curl-7.79.1-150400.5.12.1
libcurl-devel-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
libcurl4-32bit-7.79.1-150400.5.12.1
Image SLES15-SP5-SAP-Azure-3P
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-SAP-Azure-LI-BYOS
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-SAP-Azure-LI-BYOS-Production
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-SAP-Azure-VLI-BYOS
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-SAP-Azure-VLI-BYOS-Production
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-SAP-BYOS-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-SAP-BYOS-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-SAP-BYOS-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-SAP-EC2
curl-7.79.1-150400.5.12.1
libcurl-devel-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
libcurl4-32bit-7.79.1-150400.5.12.1
Image SLES15-SP5-SAP-GCE
curl-7.79.1-150400.5.12.1
libcurl-devel-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
libcurl4-32bit-7.79.1-150400.5.12.1
Image SLES15-SP5-SAP-Hardened-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-SAP-Hardened-BYOS-Azure
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-SAP-Hardened-BYOS-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-SAP-Hardened-BYOS-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-SAP-Hardened-EC2
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-SAP-Hardened-GCE
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
Image SLES15-SP5-SAPCAL-Azure
curl-7.79.1-150400.5.12.1
libcurl-devel-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
libcurl4-32bit-7.79.1-150400.5.12.1
Image SLES15-SP5-SAPCAL-EC2
curl-7.79.1-150400.5.12.1
libcurl-devel-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
libcurl4-32bit-7.79.1-150400.5.12.1
Image SLES15-SP5-SAPCAL-GCE
curl-7.79.1-150400.5.12.1
libcurl-devel-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
libcurl4-32bit-7.79.1-150400.5.12.1
SUSE Linux Enterprise Micro 5.3
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP4
curl-7.79.1-150400.5.12.1
libcurl-devel-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
libcurl4-32bit-7.79.1-150400.5.12.1
openSUSE Leap 15.4
curl-7.79.1-150400.5.12.1
libcurl-devel-7.79.1-150400.5.12.1
libcurl-devel-32bit-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1
libcurl4-32bit-7.79.1-150400.5.12.1
openSUSE Leap Micro 5.3
curl-7.79.1-150400.5.12.1
libcurl4-7.79.1-150400.5.12.1

Описание

A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. However, the HSTS mechanism could be bypassed if the host name in the given URL first uses IDN characters that get replaced to ASCII counterparts as part of the IDN conversion. Like using the character UTF-8 U+3002 (IDEOGRAPHIC FULL STOP) instead of the common ASCII full stop (U+002E) `.`. Then in a subsequent request, it does not detect the HSTS state and makes a clear text transfer. Because it would store the info IDN encoded but look for it IDN decoded.


Затронутые продукты
Container bci/bci-init:15.4:libcurl4-7.79.1-150400.5.12.1
Container bci/dotnet-aspnet:3.1:libcurl4-7.79.1-150400.5.12.1
Container bci/dotnet-aspnet:5.0:libcurl4-7.79.1-150400.5.12.1
Container bci/dotnet-aspnet:6.0:libcurl4-7.79.1-150400.5.12.1

Ссылки

Описание

A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.


Затронутые продукты
Container bci/bci-init:15.4:libcurl4-7.79.1-150400.5.12.1
Container bci/dotnet-aspnet:3.1:libcurl4-7.79.1-150400.5.12.1
Container bci/dotnet-aspnet:5.0:libcurl4-7.79.1-150400.5.12.1
Container bci/dotnet-aspnet:6.0:libcurl4-7.79.1-150400.5.12.1

Ссылки
Уязвимость SUSE-SU-2022:4597-1