Lucene search

K
redhatRedHatRHSA-2020:0544
HistoryFeb 18, 2020 - 1:56 p.m.

(RHSA-2020:0544) Moderate: curl security update

2020-02-1813:56:21
access.redhat.com
46

0.009 Low

EPSS

Percentile

82.8%

The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.

Security Fix(es):

  • curl: HTTP authentication leak in redirects (CVE-2018-1000007)

  • curl: FTP path trickery leads to NIL byte out of bounds write (CVE-2018-1000120)

  • curl: RTSP RTP buffer over-read (CVE-2018-1000122)

  • curl: Out-of-bounds heap read when missing RTSP headers allows information leak or denial of service (CVE-2018-1000301)

  • curl: LDAP NULL pointer dereference (CVE-2018-1000121)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.