exploit the possibilities

Mandriva Linux Security Advisory 2012-058

Mandriva Linux Security Advisory 2012-058
Posted Apr 13, 2012
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2012-058 - curl is vulnerable to a SSL CBC IV vulnerability when built to use OpenSSL for the SSL/TLS layer. A work-around has been added to mitigate the problem. curl is vulnerable to a data injection attack for certain protocols through control characters embedded or percent-encoded in URLs. The updated packages have been patched to correct these issues.

tags | advisory, protocol
systems | linux, mandriva
advisories | CVE-2011-3389, CVE-2012-0036
MD5 | 34beae45285f6850ee0d22f9391e3383

Mandriva Linux Security Advisory 2012-058

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2012:058
http://www.mandriva.com/security/
_______________________________________________________________________

Package : curl
Date : April 13, 2012
Affected: 2010.1, 2011.
_______________________________________________________________________

Problem Description:

Multiple vulnerabilities has been found and corrected in curl:

curl is vulnerable to a SSL CBC IV vulnerability when built to use
OpenSSL for the SSL/TLS layer. A work-around has been added to mitigate
the problem (CVE-2011-3389).

curl is vulnerable to a data injection attack for certain protocols
through control characters embedded or percent-encoded in URLs
(CVE-2012-0036).

The updated packages have been patched to correct these issues.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3389
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0036
http://curl.haxx.se/docs/adv_20120124B.html
http://thread.gmane.org/gmane.comp.web.curl.library/34659
http://curl.haxx.se/libcurl/c/curl_easy_setopt.html#CURLOPTSSLOPTIONS
http://curl.haxx.se/docs/manpage.html#--ssl-allow-beast
http://curl.haxx.se/docs/adv_20120124.html
_______________________________________________________________________

Updated Packages:

Mandriva Linux 2010.1:
2bdc2242df0233c3e0b3b259d772decc 2010.1/i586/curl-7.20.1-2.2mdv2010.2.i586.rpm
514a3c248b06b1003ca879a2f6836fd6 2010.1/i586/curl-examples-7.20.1-2.2mdv2010.2.i586.rpm
94af6abc58dc950e22d109f054ec970b 2010.1/i586/libcurl4-7.20.1-2.2mdv2010.2.i586.rpm
12d9e5f39c9617da8a0e795820e7b4d5 2010.1/i586/libcurl-devel-7.20.1-2.2mdv2010.2.i586.rpm
4a4a0081446bd7b7ea0ca5c2597af8d4 2010.1/SRPMS/curl-7.20.1-2.2mdv2010.2.src.rpm

Mandriva Linux 2010.1/X86_64:
0319e4b64c85f421fd234aa60e795e0a 2010.1/x86_64/curl-7.20.1-2.2mdv2010.2.x86_64.rpm
e27cc075785a8920d1ef3e3cd7550b63 2010.1/x86_64/curl-examples-7.20.1-2.2mdv2010.2.x86_64.rpm
6bc1a150e02f3d6315e2a69c106aedd8 2010.1/x86_64/lib64curl4-7.20.1-2.2mdv2010.2.x86_64.rpm
834d8fa9140bbc8e157f897a4dda3567 2010.1/x86_64/lib64curl-devel-7.20.1-2.2mdv2010.2.x86_64.rpm
4a4a0081446bd7b7ea0ca5c2597af8d4 2010.1/SRPMS/curl-7.20.1-2.2mdv2010.2.src.rpm

Mandriva Linux 2011:
6445b9b47ca90ff11912a6793a2f4fb9 2011/i586/curl-7.21.7-1.1-mdv2011.0.i586.rpm
d0b92983656b8629903f9bf2bbfbc43b 2011/i586/curl-examples-7.21.7-1.1-mdv2011.0.i586.rpm
2bc028afacef4e47af3597d71b594fd7 2011/i586/libcurl4-7.21.7-1.1-mdv2011.0.i586.rpm
28dc517658b4b5e0d9e2204da6b2d603 2011/i586/libcurl-devel-7.21.7-1.1-mdv2011.0.i586.rpm
2194276240c12c866c31fba743ea9ee4 2011/SRPMS/curl-7.21.7-1.1.src.rpm

Mandriva Linux 2011/X86_64:
8566de165a109b88c211731f84d5279a 2011/x86_64/curl-7.21.7-1.1-mdv2011.0.x86_64.rpm
1a9dcb47bb78ebcff2c2242be198c59f 2011/x86_64/curl-examples-7.21.7-1.1-mdv2011.0.x86_64.rpm
9b75a29092361b8f7c9d6ffebb6cec48 2011/x86_64/lib64curl4-7.21.7-1.1-mdv2011.0.x86_64.rpm
82b79d8ba65b018eb34d35ad3a1cb643 2011/x86_64/lib64curl-devel-7.21.7-1.1-mdv2011.0.x86_64.rpm
2194276240c12c866c31fba743ea9ee4 2011/SRPMS/curl-7.21.7-1.1.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iD8DBQFPh/bqmqjQ0CJFipgRAiSYAJ4yXLe6WID+QOHJE93WaUu4KC3jbwCeKTF4
a0gDzhUStZY5833ISoU0w+A=
=V7xb
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

November 2020

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    2 Files
  • 2
    Nov 2nd
    9 Files
  • 3
    Nov 3rd
    15 Files
  • 4
    Nov 4th
    90 Files
  • 5
    Nov 5th
    22 Files
  • 6
    Nov 6th
    16 Files
  • 7
    Nov 7th
    1 Files
  • 8
    Nov 8th
    1 Files
  • 9
    Nov 9th
    40 Files
  • 10
    Nov 10th
    27 Files
  • 11
    Nov 11th
    28 Files
  • 12
    Nov 12th
    13 Files
  • 13
    Nov 13th
    18 Files
  • 14
    Nov 14th
    2 Files
  • 15
    Nov 15th
    2 Files
  • 16
    Nov 16th
    29 Files
  • 17
    Nov 17th
    15 Files
  • 18
    Nov 18th
    15 Files
  • 19
    Nov 19th
    21 Files
  • 20
    Nov 20th
    16 Files
  • 21
    Nov 21st
    1 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    19 Files
  • 24
    Nov 24th
    32 Files
  • 25
    Nov 25th
    7 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2020 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close