First published: Tue Feb 25 2020(Updated: )
The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.<br>Security Fix(es):<br><li> curl: HTTP authentication leak in redirects (CVE-2018-1000007)</li> <li> curl: FTP path trickery leads to NIL byte out of bounds write (CVE-2018-1000120)</li> <li> curl: RTSP RTP buffer over-read (CVE-2018-1000122)</li> <li> curl: Out-of-bounds heap read when missing RTSP headers allows information leak or denial of service (CVE-2018-1000301)</li> <li> curl: LDAP NULL pointer dereference (CVE-2018-1000121)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/curl | <7.29.0-42.el7_4.2 | 7.29.0-42.el7_4.2 |
redhat/curl | <7.29.0-42.el7_4.2 | 7.29.0-42.el7_4.2 |
redhat/curl-debuginfo | <7.29.0-42.el7_4.2 | 7.29.0-42.el7_4.2 |
redhat/curl-debuginfo | <7.29.0-42.el7_4.2 | 7.29.0-42.el7_4.2 |
redhat/libcurl | <7.29.0-42.el7_4.2 | 7.29.0-42.el7_4.2 |
redhat/libcurl | <7.29.0-42.el7_4.2 | 7.29.0-42.el7_4.2 |
redhat/libcurl-devel | <7.29.0-42.el7_4.2 | 7.29.0-42.el7_4.2 |
redhat/libcurl-devel | <7.29.0-42.el7_4.2 | 7.29.0-42.el7_4.2 |
redhat/curl | <7.29.0-42.el7_4.2 | 7.29.0-42.el7_4.2 |
redhat/curl-debuginfo | <7.29.0-42.el7_4.2 | 7.29.0-42.el7_4.2 |
redhat/libcurl | <7.29.0-42.el7_4.2 | 7.29.0-42.el7_4.2 |
redhat/libcurl-devel | <7.29.0-42.el7_4.2 | 7.29.0-42.el7_4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.