Описание
Security update for curl
This update for curl fixes the following issues:
This update for curl fixes the following issues:
- CVE-2025-14017: broken TLS options for threaded LDAPS (bsc#1256105).
- CVE-2025-14524: bearer token leak on cross-protocol redirect (bsc#1255731).
- CVE-2025-14819: libssh global knownhost override (bsc#1255732).
- CVE-2025-15079: libssh key passphrase bypass without agent set (bsc#1255733).
- CVE-2025-15224: OpenSSL partial chain store policy bypass (bsc#1255734).
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1255731
- SUSE Bug 1255732
- SUSE Bug 1255733
- SUSE Bug 1255734
- SUSE Bug 1256105
- SUSE CVE CVE-2025-14017 page
- SUSE CVE CVE-2025-14524 page
- SUSE CVE CVE-2025-14819 page
- SUSE CVE CVE-2025-15079 page
- SUSE CVE CVE-2025-15224 page
Описание
When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers. Disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well.
Затронутые продукты
Ссылки
- CVE-2025-14017
- SUSE Bug 1256105
Описание
When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a cross-protocol redirect to a second URL that uses an IMAP, LDAP, POP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new target host.
Затронутые продукты
Ссылки
- CVE-2025-14524
- SUSE Bug 1255731
Описание
When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept a trust chain that it otherwise would not.
Затронутые продукты
Ссылки
- CVE-2025-14819
- SUSE Bug 1255732
Описание
When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file.
Затронутые продукты
Ссылки
- CVE-2025-15079
- SUSE Bug 1255733
Описание
When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.
Затронутые продукты
Ссылки
- CVE-2025-15224
- SUSE Bug 1255734