what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Debian Security Advisory 4098-1

Debian Security Advisory 4098-1
Posted Jan 29, 2018
Authored by Debian | Site debian.org

Debian Linux Security Advisory 4098-1 - Two vulnerabilities were discovered in cURL, an URL transfer library.

tags | advisory, vulnerability
systems | linux, debian
advisories | CVE-2018-1000005, CVE-2018-1000007
SHA-256 | 376ed0f70b86b9d1733f4b3f86cbfbef6a864d40c5ef179cca6809993ca03119

Debian Security Advisory 4098-1

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4098-1 security@debian.org
https://www.debian.org/security/ Alessandro Ghedini
January 26, 2018 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : curl
CVE ID : CVE-2018-1000005 CVE-2018-1000007

Two vulnerabilities were discovered in cURL, an URL transfer library.

CVE-2018-1000005

Zhouyihai Ding discovered an out-of-bounds read in the code
handling HTTP/2 trailers. This issue doesn't affect the oldstable
distribution (jessie).

CVE-2018-1000007

Craig de Stigter discovered that authentication data might be leaked
to third parties when following HTTP redirects.

For the oldstable distribution (jessie), these problems have been fixed
in version 7.38.0-4+deb8u9.

For the stable distribution (stretch), these problems have been fixed in
version 7.52.1-5+deb9u4.

We recommend that you upgrade your curl packages.

For the detailed security status of curl please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/curl

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEBsId305pBx+F583DbwzL4CFiRygFAlpq+YMACgkQbwzL4CFi
RygoCRAArQKcYRR1ay6Qbj4HHMINwJAcPo7PgtRREFjzkffKOd98SbJU+QN8MNT9
USe/OEnjRM5d7iTk5pqZBCH9wjm0KSCtq4nko1lSxnFUtjJfi1CNz2chFYKnR9/w
OTG6SNzQXoxO56q2e6vYbh5CFbXbpJfuc6xUdSSjgkXWnFFXBYwB83YpouF7pTWK
DFVW6ZTxt7xig8RrO7Q6+7+m2qxEW+raaDBUwgczxMTZc50uqzN+MH61QH99Jljn
tRhT7/weEZV4Uiu3Q8aY8ERJsOClE8tdlT5MDp5IxQYAm8A9I4GgB+mRkh0+Z29Y
J8QKg4jI7MaEGWN342HTwyiFvGjHsFqa4wQzEyMKM6PJo5Herti5xOQbPVGWnMQX
dVzO+wU9lu3zitWPSdNXFV9jKHF0nrHIrTEWcTVk0L30oVe3xN3GmW/PCxKWO1JD
hzNwwReQ/CUi7+4Ww9qmpcQGSvTk5uO+PdywoPs0cqP4qsPln3ENDf/4UXQdQ2pZ
7jh9rT+WJ0m/3RAX6yBQoZfSbhSJD+ZsPTrdV0fWIW9PW9c8fjXnkzIOZNeYFKxH
XLyiDRtJszZ5DvSpMKZaFghaICHRlbe4sdGj7gyQ4f00ypPtEXz+LDDVD/mAK3ou
d4/x0/0W6T5h4nWdMqE9k1aInKJJcVE1lJvAFqM8QqEZw5I5Vbg=
=68U/
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    0 Files
  • 6
    Aug 6th
    0 Files
  • 7
    Aug 7th
    0 Files
  • 8
    Aug 8th
    0 Files
  • 9
    Aug 9th
    0 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close