Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:2784-1

Опубликовано: 06 авг. 2024
Источник: suse-cvrf

Описание

Security update for curl

This update for curl fixes the following issues:

  • CVE-2024-7264: Fixed ASN.1 date parser overread (bsc#1228535)
  • CVE-2024-6197: Fixed freeing stack buffer in utf8asn1str (bsc#1227888)

Список пакетов

Container bci/bci-sle15-kernel-module-devel:15.7
libcurl4-8.6.0-150600.4.3.1
Container bci/bci-sle15-kernel-module-devel:latest
libcurl4-8.6.0-150600.4.3.1
Container bci/gcc:latest
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container bci/golang:1.22-openssl
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container bci/golang:1.23
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container bci/golang:latest
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container bci/kiwi:latest
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container bci/node:22
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container bci/nodejs:latest
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container bci/openjdk:17
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container bci/openjdk:latest
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container bci/php-apache:latest
libcurl4-8.6.0-150600.4.3.1
Container bci/php-fpm:latest
libcurl4-8.6.0-150600.4.3.1
Container bci/php:latest
libcurl4-8.6.0-150600.4.3.1
Container bci/python:3
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container bci/python:3.13
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container bci/python:latest
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container bci/ruby:3
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container bci/ruby:latest
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container bci/rust:1.84
libcurl4-8.6.0-150600.4.3.1
Container bci/rust:latest
libcurl4-8.6.0-150600.4.3.1
Container bci/spack:0.23
curl-8.6.0-150600.4.3.1
libcurl-devel-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container bci/spack:latest
curl-8.6.0-150600.4.3.1
libcurl-devel-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container containers/apache-pulsar:3.3
libcurl4-8.6.0-150600.4.3.1
Container containers/milvus:2.4
libcurl4-8.6.0-150600.4.3.1
Container containers/open-webui:0
libcurl4-8.6.0-150600.4.3.1
Container containers/python:3.11
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container containers/python:3.9
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container containers/pytorch:2-nvidia
libcurl4-8.6.0-150600.4.3.1
Container containers/pytorch:2.5.0
libcurl4-8.6.0-150600.4.3.1
Container suse/git:latest
libcurl4-8.6.0-150600.4.3.1
Container suse/hpc/warewulf4-x86_64/sle-hpc-node:latest
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container suse/manager/5.0/x86_64/proxy-httpd:latest
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container suse/manager/5.0/x86_64/proxy-salt-broker:latest
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container suse/manager/5.0/x86_64/server-hub-xmlrpc-api:latest
libcurl4-8.6.0-150600.4.3.1
Container suse/manager/5.0/x86_64/server:latest
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container suse/sle15:15.6
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container suse/sle15:15.7
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container suse/sles/15.7/cdi-cloner:1.58.0
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container suse/sles/15.7/cdi-importer:1.58.0
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container suse/sles/15.7/cdi-uploadserver:1.58.0
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container suse/sles/15.7/libguestfs-tools:1.4.0
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container suse/sles/15.7/virt-handler:1.4.0
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container suse/sles/15.7/virt-launcher:1.4.0
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Container trento/trento-wanda:latest
libcurl4-8.6.0-150600.4.3.1
Container trento/trento-web:latest
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-Azure-Basic
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-Azure-Standard
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-BYOS
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-BYOS-Azure
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-BYOS-EC2
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-BYOS-GCE
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-CHOST-BYOS
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-CHOST-BYOS-Aliyun
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-CHOST-BYOS-Azure
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-CHOST-BYOS-EC2
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-CHOST-BYOS-GCE
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-CHOST-BYOS-GDC
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-CHOST-BYOS-SAP-CCloud
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-EC2
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-EC2-ECS-HVM
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-GCE
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-HPC
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-HPC-Azure
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-HPC-BYOS
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-HPC-BYOS-Azure
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-HPC-BYOS-EC2
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-HPC-BYOS-GCE
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-HPC-EC2
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-HPC-GCE
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-Hardened-BYOS
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-Hardened-BYOS-Azure
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-Hardened-BYOS-EC2
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-Hardened-BYOS-GCE
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-SAP
curl-8.6.0-150600.4.3.1
libcurl-devel-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
libcurl4-32bit-8.6.0-150600.4.3.1
Image SLES15-SP6-SAP-Azure
curl-8.6.0-150600.4.3.1
libcurl-devel-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
libcurl4-32bit-8.6.0-150600.4.3.1
Image SLES15-SP6-SAP-Azure-LI-BYOS
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-SAP-Azure-VLI-BYOS
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-SAP-Azure-VLI-BYOS-Production
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-SAP-BYOS
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-SAP-BYOS-Azure
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-SAP-BYOS-EC2
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-SAP-BYOS-GCE
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-SAP-EC2
curl-8.6.0-150600.4.3.1
libcurl-devel-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
libcurl4-32bit-8.6.0-150600.4.3.1
Image SLES15-SP6-SAP-GCE
curl-8.6.0-150600.4.3.1
libcurl-devel-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
libcurl4-32bit-8.6.0-150600.4.3.1
Image SLES15-SP6-SAP-Hardened
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-SAP-Hardened-Azure
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-SAP-Hardened-BYOS
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-SAP-Hardened-BYOS-Azure
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-SAP-Hardened-BYOS-EC2
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-SAP-Hardened-BYOS-GCE
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-SAP-Hardened-EC2
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-SAP-Hardened-GCE
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image SLES15-SP6-SAPCAL
curl-8.6.0-150600.4.3.1
libcurl-devel-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
libcurl4-32bit-8.6.0-150600.4.3.1
Image SLES15-SP6-SAPCAL-Azure
curl-8.6.0-150600.4.3.1
libcurl-devel-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
libcurl4-32bit-8.6.0-150600.4.3.1
Image SLES15-SP6-SAPCAL-EC2
curl-8.6.0-150600.4.3.1
libcurl-devel-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
libcurl4-32bit-8.6.0-150600.4.3.1
Image SLES15-SP6-SAPCAL-GCE
curl-8.6.0-150600.4.3.1
libcurl-devel-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
libcurl4-32bit-8.6.0-150600.4.3.1
Image ai_15_6
libcurl4-8.6.0-150600.4.3.1
Image proxy-httpd-image
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image proxy-salt-broker-image
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image python_15_6
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
Image server-hub-xmlrpc-api-image
libcurl4-8.6.0-150600.4.3.1
Image server-image
curl-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
SUSE Linux Enterprise Module for Basesystem 15 SP6
curl-8.6.0-150600.4.3.1
libcurl-devel-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
libcurl4-32bit-8.6.0-150600.4.3.1
openSUSE Leap 15.6
curl-8.6.0-150600.4.3.1
libcurl-devel-8.6.0-150600.4.3.1
libcurl-devel-32bit-8.6.0-150600.4.3.1
libcurl4-8.6.0-150600.4.3.1
libcurl4-32bit-8.6.0-150600.4.3.1

Описание

libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `free()` on a 4 byte localstack buffer. Most modern malloc implementations detect this error and immediately abort. Some however accept the input pointer and add that memory to its list of available chunks. This leads to the overwriting of nearby stack memory. The content of the overwrite is decided by the `free()` implementation; likely to be memory pointers and a set of flags. The most likely outcome of exploting this flaw is a crash, although it cannot be ruled out that more serious results can be had in special circumstances.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:15.7:libcurl4-8.6.0-150600.4.3.1
Container bci/bci-sle15-kernel-module-devel:latest:libcurl4-8.6.0-150600.4.3.1
Container bci/gcc:latest:curl-8.6.0-150600.4.3.1
Container bci/gcc:latest:libcurl4-8.6.0-150600.4.3.1

Ссылки

Описание

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.


Затронутые продукты
Container bci/bci-sle15-kernel-module-devel:15.7:libcurl4-8.6.0-150600.4.3.1
Container bci/bci-sle15-kernel-module-devel:latest:libcurl4-8.6.0-150600.4.3.1
Container bci/gcc:latest:curl-8.6.0-150600.4.3.1
Container bci/gcc:latest:libcurl4-8.6.0-150600.4.3.1

Ссылки
Уязвимость SUSE-SU-2024:2784-1