Описание
Security update for curl
This update for curl fixes the following issues:
- CVE-2025-9086: bug in path comparison logic when processing cookies can lead to out-of-bounds read in heap buffer (bsc#1249191).
- CVE-2025-10148: predictable websocket mask can lead to proxy cache poisoning by malicious server (bsc#1249348).
Список пакетов
Container suse/ltss/sle12.5/sles12sp5:latest
libcurl4-8.0.1-11.108.1
SUSE Linux Enterprise Server 12 SP5-LTSS
curl-8.0.1-11.108.1
libcurl-devel-8.0.1-11.108.1
libcurl4-8.0.1-11.108.1
libcurl4-32bit-8.0.1-11.108.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
curl-8.0.1-11.108.1
libcurl-devel-8.0.1-11.108.1
libcurl4-8.0.1-11.108.1
libcurl4-32bit-8.0.1-11.108.1
Ссылки
- Link for SUSE-SU-2025:03173-1
- E-Mail link for SUSE-SU-2025:03173-1
- SUSE Security Ratings
- SUSE Bug 1249191
- SUSE Bug 1249348
- SUSE CVE CVE-2025-10148 page
- SUSE CVE CVE-2025-9086 page
Описание
unknown
Затронутые продукты
Container suse/ltss/sle12.5/sles12sp5:latest:libcurl4-8.0.1-11.108.1
SUSE Linux Enterprise Server 12 SP5-LTSS:curl-8.0.1-11.108.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libcurl-devel-8.0.1-11.108.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libcurl4-32bit-8.0.1-11.108.1
Ссылки
- CVE-2025-10148
- SUSE Bug 1249348
Описание
unknown
Затронутые продукты
Container suse/ltss/sle12.5/sles12sp5:latest:libcurl4-8.0.1-11.108.1
SUSE Linux Enterprise Server 12 SP5-LTSS:curl-8.0.1-11.108.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libcurl-devel-8.0.1-11.108.1
SUSE Linux Enterprise Server 12 SP5-LTSS:libcurl4-32bit-8.0.1-11.108.1
Ссылки
- CVE-2025-9086
- SUSE Bug 1249191