Описание
Security update for curl
This update for curl fixes the following issues:
- CVE-2024-11053: Fixed password leak in curl used for the first host to the followed-to host under certain circumstances (bsc#1234068)
Список пакетов
Container suse/ltss/sle12.5/sles12sp5:latest
libcurl4-8.0.1-11.101.1
Image SLES12-SP5-Azure-BYOS
curl-8.0.1-11.101.1
libcurl4-8.0.1-11.101.1
Image SLES12-SP5-Azure-HPC-BYOS
curl-8.0.1-11.101.1
libcurl4-8.0.1-11.101.1
Image SLES12-SP5-Azure-HPC-On-Demand
curl-8.0.1-11.101.1
libcurl4-8.0.1-11.101.1
Image SLES12-SP5-Azure-SAP-BYOS
curl-8.0.1-11.101.1
libcurl4-8.0.1-11.101.1
Image SLES12-SP5-Azure-SAP-On-Demand
curl-8.0.1-11.101.1
libcurl4-8.0.1-11.101.1
Image SLES12-SP5-Azure-Standard-On-Demand
curl-8.0.1-11.101.1
libcurl4-8.0.1-11.101.1
Image SLES12-SP5-EC2-BYOS
curl-8.0.1-11.101.1
libcurl4-8.0.1-11.101.1
Image SLES12-SP5-EC2-ECS-On-Demand
libcurl4-8.0.1-11.101.1
Image SLES12-SP5-EC2-On-Demand
curl-8.0.1-11.101.1
libcurl4-8.0.1-11.101.1
Image SLES12-SP5-EC2-SAP-BYOS
curl-8.0.1-11.101.1
libcurl4-8.0.1-11.101.1
Image SLES12-SP5-EC2-SAP-On-Demand
curl-8.0.1-11.101.1
libcurl4-8.0.1-11.101.1
Image SLES12-SP5-GCE-BYOS
curl-8.0.1-11.101.1
libcurl4-8.0.1-11.101.1
Image SLES12-SP5-GCE-On-Demand
curl-8.0.1-11.101.1
libcurl4-8.0.1-11.101.1
Image SLES12-SP5-GCE-SAP-BYOS
curl-8.0.1-11.101.1
libcurl4-8.0.1-11.101.1
Image SLES12-SP5-GCE-SAP-On-Demand
curl-8.0.1-11.101.1
libcurl4-8.0.1-11.101.1
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
curl-8.0.1-11.101.1
libcurl4-8.0.1-11.101.1
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
curl-8.0.1-11.101.1
libcurl4-8.0.1-11.101.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
curl-8.0.1-11.101.1
libcurl-devel-8.0.1-11.101.1
libcurl4-8.0.1-11.101.1
libcurl4-32bit-8.0.1-11.101.1
Ссылки
- Link for SUSE-SU-2024:4284-1
- E-Mail link for SUSE-SU-2024:4284-1
- SUSE Security Ratings
- SUSE Bug 1234068
- SUSE CVE CVE-2024-11053 page
Описание
When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password.
Затронутые продукты
Container suse/ltss/sle12.5/sles12sp5:latest:libcurl4-8.0.1-11.101.1
Image SLES12-SP5-Azure-BYOS:curl-8.0.1-11.101.1
Image SLES12-SP5-Azure-BYOS:libcurl4-8.0.1-11.101.1
Image SLES12-SP5-Azure-HPC-BYOS:curl-8.0.1-11.101.1
Ссылки
- CVE-2024-11053
- SUSE Bug 1234068