Lucene search

K
slackwareSlackware Linux ProjectSSA-2021-258-01
HistorySep 16, 2021 - 3:11 a.m.

[slackware-security] curl

2021-09-1603:11:12
Slackware Linux Project
www.slackware.com
80
slackware
security fix
curl
upgrade
ftp hosting
osu open source lab

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:N/A:P

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

EPSS

0.007

Percentile

80.2%

New curl packages are available for Slackware 14.0, 14.1, 14.2, and -current to
fix security issues.

Here are the details from the Slackware 14.2 ChangeLog:

patches/packages/curl-7.79.0-i586-1_slack14.2.txz: Upgraded.
This update fixes security issues:
clear the leftovers pointer when sending succeeds.
do not ignore --ssl-reqd.
reject STARTTLS server response pipelining.
For more information, see:
https://vulners.com/cve/CVE-2021-22945
https://vulners.com/cve/CVE-2021-22946
https://vulners.com/cve/CVE-2021-22947
(* Security fix *)

Where to find the new packages:

Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)

Also see the “Get Slack” section on http://slackware.com for
additional mirror sites near you.

Updated package for Slackware 14.0:
ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/curl-7.79.0-i486-1_slack14.0.txz

Updated package for Slackware x86_64 14.0:
ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/curl-7.79.0-x86_64-1_slack14.0.txz

Updated package for Slackware 14.1:
ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/curl-7.79.0-i486-1_slack14.1.txz

Updated package for Slackware x86_64 14.1:
ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/curl-7.79.0-x86_64-1_slack14.1.txz

Updated package for Slackware 14.2:
ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/curl-7.79.0-i586-1_slack14.2.txz

Updated package for Slackware x86_64 14.2:
ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/curl-7.79.0-x86_64-1_slack14.2.txz

Updated package for Slackware -current:
ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/curl-7.79.0-i586-1.txz

Updated package for Slackware x86_64 -current:
ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/curl-7.79.0-x86_64-1.txz

MD5 signatures:

Slackware 14.0 package:
a311694304f739d807ec1c3f1e1be430 curl-7.79.0-i486-1_slack14.0.txz

Slackware x86_64 14.0 package:
131de90d080e29b34397a7fdb323e763 curl-7.79.0-x86_64-1_slack14.0.txz

Slackware 14.1 package:
f1e61ff5609bf1e9abfd0a6d0130b115 curl-7.79.0-i486-1_slack14.1.txz

Slackware x86_64 14.1 package:
61cd3800c0f47a45b63553edcc1efe59 curl-7.79.0-x86_64-1_slack14.1.txz

Slackware 14.2 package:
ed6337cdae711195c4068162041dae80 curl-7.79.0-i586-1_slack14.2.txz

Slackware x86_64 14.2 package:
8fc49031584a53e35f85b32bf3726e00 curl-7.79.0-x86_64-1_slack14.2.txz

Slackware -current package:
661f22d3b107a2a1f7936b3c19597fe0 n/curl-7.79.0-i586-1.txz

Slackware x86_64 -current package:
cede4ac1b79cc400c7f4112fff5d69d6 n/curl-7.79.0-x86_64-1.txz

Installation instructions:

Upgrade the package as root:
> upgradepkg curl-7.79.0-i586-1_slack14.2.txz

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:N/A:P

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

EPSS

0.007

Percentile

80.2%