Описание
Security update for curl
This update for curl fixes the following issues:
Following security issues were fixed:
- CVE-2018-1000120: A buffer overflow exists in the FTP URL handling that allowed an attacker to cause a denial of service or possible code execution (bsc#1084521).
- CVE-2018-1000121: A NULL pointer dereference exists in the LDAP code that allowed an attacker to cause a denial of service (bsc#1084524).
- CVE-2018-1000122: A buffer over-read exists in the RTSP+RTP handling code that allowed an attacker to cause a denial of service or information leakage (bsc#1084532).
This update was imported from the SUSE:SLE-12:Update update project.
Список пакетов
openSUSE Leap 42.3
curl-7.37.0-33.1
libcurl-devel-7.37.0-33.1
libcurl-devel-32bit-7.37.0-33.1
libcurl4-7.37.0-33.1
libcurl4-32bit-7.37.0-33.1
Ссылки
- E-Mail link for openSUSE-SU-2018:0794-1
- SUSE Security Ratings
Описание
A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or worse.
Затронутые продукты
openSUSE Leap 42.3:curl-7.37.0-33.1
openSUSE Leap 42.3:libcurl-devel-32bit-7.37.0-33.1
openSUSE Leap 42.3:libcurl-devel-7.37.0-33.1
openSUSE Leap 42.3:libcurl4-32bit-7.37.0-33.1
Ссылки
- CVE-2018-1000120
- SUSE Bug 1084521
- SUSE Bug 1101811
- SUSE Bug 1112526
Описание
A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that allows an attacker to cause a denial of service
Затронутые продукты
openSUSE Leap 42.3:curl-7.37.0-33.1
openSUSE Leap 42.3:libcurl-devel-32bit-7.37.0-33.1
openSUSE Leap 42.3:libcurl-devel-7.37.0-33.1
openSUSE Leap 42.3:libcurl4-32bit-7.37.0-33.1
Ссылки
- CVE-2018-1000121
- SUSE Bug 1084524
- SUSE Bug 1085215
- SUSE Bug 1101811
- SUSE Bug 1112526
Описание
A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of service or information leakage
Затронутые продукты
openSUSE Leap 42.3:curl-7.37.0-33.1
openSUSE Leap 42.3:libcurl-devel-32bit-7.37.0-33.1
openSUSE Leap 42.3:libcurl-devel-7.37.0-33.1
openSUSE Leap 42.3:libcurl4-32bit-7.37.0-33.1
Ссылки
- CVE-2018-1000122
- SUSE Bug 1084532
- SUSE Bug 1101811
- SUSE Bug 1112526