lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: Fri, 26 Jan 2018 09:59:00 +0000
From: Alessandro Ghedini <ghedo@...ian.org>
To: bugtraq@...urityfocus.com
Subject: [SECURITY] [DSA 4098-1] curl security update

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4098-1                   security@...ian.org
https://www.debian.org/security/                       Alessandro Ghedini
January 26, 2018                      https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : curl
CVE ID         : CVE-2018-1000005 CVE-2018-1000007

Two vulnerabilities were discovered in cURL, an URL transfer library.

CVE-2018-1000005

    Zhouyihai Ding discovered an out-of-bounds read in the code
    handling HTTP/2 trailers. This issue doesn't affect the oldstable
    distribution (jessie).

CVE-2018-1000007

    Craig de Stigter discovered that authentication data might be leaked
    to third parties when following HTTP redirects.

For the oldstable distribution (jessie), these problems have been fixed
in version 7.38.0-4+deb8u9.

For the stable distribution (stretch), these problems have been fixed in
version 7.52.1-5+deb9u4.

We recommend that you upgrade your curl packages.

For the detailed security status of curl please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/curl

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@...ts.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEBsId305pBx+F583DbwzL4CFiRygFAlpq+YMACgkQbwzL4CFi
RygoCRAArQKcYRR1ay6Qbj4HHMINwJAcPo7PgtRREFjzkffKOd98SbJU+QN8MNT9
USe/OEnjRM5d7iTk5pqZBCH9wjm0KSCtq4nko1lSxnFUtjJfi1CNz2chFYKnR9/w
OTG6SNzQXoxO56q2e6vYbh5CFbXbpJfuc6xUdSSjgkXWnFFXBYwB83YpouF7pTWK
DFVW6ZTxt7xig8RrO7Q6+7+m2qxEW+raaDBUwgczxMTZc50uqzN+MH61QH99Jljn
tRhT7/weEZV4Uiu3Q8aY8ERJsOClE8tdlT5MDp5IxQYAm8A9I4GgB+mRkh0+Z29Y
J8QKg4jI7MaEGWN342HTwyiFvGjHsFqa4wQzEyMKM6PJo5Herti5xOQbPVGWnMQX
dVzO+wU9lu3zitWPSdNXFV9jKHF0nrHIrTEWcTVk0L30oVe3xN3GmW/PCxKWO1JD
hzNwwReQ/CUi7+4Ww9qmpcQGSvTk5uO+PdywoPs0cqP4qsPln3ENDf/4UXQdQ2pZ
7jh9rT+WJ0m/3RAX6yBQoZfSbhSJD+ZsPTrdV0fWIW9PW9c8fjXnkzIOZNeYFKxH
XLyiDRtJszZ5DvSpMKZaFghaICHRlbe4sdGj7gyQ4f00ypPtEXz+LDDVD/mAK3ou
d4/x0/0W6T5h4nWdMqE9k1aInKJJcVE1lJvAFqM8QqEZw5I5Vbg=
=68U/
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux - Powered by OpenVZ