Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2018:1344-1

Опубликовано: 18 мая 2018
Источник: suse-cvrf

Описание

Security update for curl

This update for curl fixes several issues:

Security issues fixed:

  • CVE-2018-1000301: Fixed a RTSP bad headers buffer over-read could crash the curl client (bsc#1092098)

Non security issues fixed:

  • If the DEFAULT_SUSE cipher list is not available use the HIGH cipher alias before failing. (bsc#1086825)

This update was imported from the SUSE:SLE-12:Update update project.

Список пакетов

openSUSE Leap 42.3
curl-7.37.0-36.1
libcurl-devel-7.37.0-36.1
libcurl-devel-32bit-7.37.0-36.1
libcurl4-7.37.0-36.1
libcurl4-32bit-7.37.0-36.1

Описание

curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability appears to have been fixed in curl < 7.20.0 and curl >= 7.60.0.


Затронутые продукты
openSUSE Leap 42.3:curl-7.37.0-36.1
openSUSE Leap 42.3:libcurl-devel-32bit-7.37.0-36.1
openSUSE Leap 42.3:libcurl-devel-7.37.0-36.1
openSUSE Leap 42.3:libcurl4-32bit-7.37.0-36.1

Ссылки