-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4098-1 security@debian.org https://www.debian.org/security/ Alessandro Ghedini January 26, 2018 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : curl CVE ID : CVE-2018-1000005 CVE-2018-1000007 Two vulnerabilities were discovered in cURL, an URL transfer library. CVE-2018-1000005 Zhouyihai Ding discovered an out-of-bounds read in the code handling HTTP/2 trailers. This issue doesn't affect the oldstable distribution (jessie). CVE-2018-1000007 Craig de Stigter discovered that authentication data might be leaked to third parties when following HTTP redirects. For the oldstable distribution (jessie), these problems have been fixed in version 7.38.0-4+deb8u9. For the stable distribution (stretch), these problems have been fixed in version 7.52.1-5+deb9u4. We recommend that you upgrade your curl packages. For the detailed security status of curl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/curl Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEBsId305pBx+F583DbwzL4CFiRygFAlpq+YMACgkQbwzL4CFi RygoCRAArQKcYRR1ay6Qbj4HHMINwJAcPo7PgtRREFjzkffKOd98SbJU+QN8MNT9 USe/OEnjRM5d7iTk5pqZBCH9wjm0KSCtq4nko1lSxnFUtjJfi1CNz2chFYKnR9/w OTG6SNzQXoxO56q2e6vYbh5CFbXbpJfuc6xUdSSjgkXWnFFXBYwB83YpouF7pTWK DFVW6ZTxt7xig8RrO7Q6+7+m2qxEW+raaDBUwgczxMTZc50uqzN+MH61QH99Jljn tRhT7/weEZV4Uiu3Q8aY8ERJsOClE8tdlT5MDp5IxQYAm8A9I4GgB+mRkh0+Z29Y J8QKg4jI7MaEGWN342HTwyiFvGjHsFqa4wQzEyMKM6PJo5Herti5xOQbPVGWnMQX dVzO+wU9lu3zitWPSdNXFV9jKHF0nrHIrTEWcTVk0L30oVe3xN3GmW/PCxKWO1JD hzNwwReQ/CUi7+4Ww9qmpcQGSvTk5uO+PdywoPs0cqP4qsPln3ENDf/4UXQdQ2pZ 7jh9rT+WJ0m/3RAX6yBQoZfSbhSJD+ZsPTrdV0fWIW9PW9c8fjXnkzIOZNeYFKxH XLyiDRtJszZ5DvSpMKZaFghaICHRlbe4sdGj7gyQ4f00ypPtEXz+LDDVD/mAK3ou d4/x0/0W6T5h4nWdMqE9k1aInKJJcVE1lJvAFqM8QqEZw5I5Vbg= =68U/ -----END PGP SIGNATURE-----