4.3 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:M/Au:N/C:P/I:N/A:N
7.5 High
AI Score
Confidence
Low
0.009 Low
EPSS
Percentile
82.3%
Debian Security Advisory DSA-2398-2 [email protected]
http://www.debian.org/security/ Florian Weimer
March 31, 2012 http://www.debian.org/security/faq
Package : curl
Vulnerability : regression
Debian-specific: no
Debian Bug : 658276
cURL is a command-line tool and library for transferring data with URL
syntax. It was discovered that the countermeasures against the
Dai/Rogaway chosen-plaintext attack on SSL/TLS (CVE-2011-3389,
"BEAST") cause interoperability issues with some server
implementations. This update ads the the CURLOPT_SSL_OPTIONS and
CURLSSLOPT_ALLOW_BEAST options to the library, and the
For the stable distribution (squeeze), this problem has been fixed in
version 7.21.0-2.1+squeeze2.
We recommend that you upgrade your curl packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: [email protected]
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 6 | mipsel | libcurl3-gnutls | < 7.21.0-2.1+squeeze1 | libcurl3-gnutls_7.21.0-2.1+squeeze1_mipsel.deb |
Debian | 6 | s390 | libcurl4-gnutls-dev | < 7.21.0-2.1+squeeze1 | libcurl4-gnutls-dev_7.21.0-2.1+squeeze1_s390.deb |
Debian | 6 | armel | libcurl3-gnutls | < 7.21.0-2.1+squeeze1 | libcurl3-gnutls_7.21.0-2.1+squeeze1_armel.deb |
Debian | 5 | amd64 | libcurl3-dbg | < 7.18.2-8lenny6 | libcurl3-dbg_7.18.2-8lenny6_amd64.deb |
Debian | 6 | powerpc | libcurl3 | < 7.21.0-2.1+squeeze1 | libcurl3_7.21.0-2.1+squeeze1_powerpc.deb |
Debian | 5 | i386 | libcurl3-gnutls | < 7.18.2-8lenny6 | libcurl3-gnutls_7.18.2-8lenny6_i386.deb |
Debian | 5 | arm | libcurl4-openssl-dev | < 7.18.2-8lenny6 | libcurl4-openssl-dev_7.18.2-8lenny6_arm.deb |
Debian | 6 | mips | libcurl3-dbg | < 7.21.0-2.1+squeeze1 | libcurl3-dbg_7.21.0-2.1+squeeze1_mips.deb |
Debian | 6 | armel | libcurl4-gnutls-dev | < 7.21.0-2.1+squeeze1 | libcurl4-gnutls-dev_7.21.0-2.1+squeeze1_armel.deb |
Debian | 6 | s390 | libcurl4-openssl-dev | < 7.21.0-2.1+squeeze1 | libcurl4-openssl-dev_7.21.0-2.1+squeeze1_s390.deb |