Lucene search

K
redhatRedHatRHSA-2017:0847
HistoryMar 29, 2017 - 5:37 a.m.

(RHSA-2017:0847) Moderate: curl security update

2017-03-2905:37:28
access.redhat.com
40

0.005 Low

EPSS

Percentile

77.5%

The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.

Security Fix(es):

  • It was found that the fix for CVE-2015-3148 in curl was incomplete. An application using libcurl with HTTP Negotiate authentication could incorrectly re-use credentials for subsequent requests to the same server. (CVE-2017-2628)

This issue was discovered by Paulo Andrade (Red Hat).