[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2017:1042-1 -- SLES curl, libcurl4

ID: oval:org.secpod.oval:def:89044855Date: (C)2021-07-20   (M)2022-10-10
Class: PATCHFamily: unix




This update for curl fixes the following issues: Security issue fixed: - CVE-2016-9586: libcurl printf floating point buffer overflow - CVE-2017-7407: The ourWriteOut function in tool_writeout.c in curl might have allowed physically proximate attackers to obtain sensitive information from process memory in opportunistic circumstances by reading a workstation screen during use of a --write-out argument ending in a "%" character, which lead to a heap-based buffer over-read . With this release new default ciphers are active .

Platform:
SUSE Linux Enterprise Server 12 SP2
Product:
curl
libcurl4
Reference:
SUSE-SU-2017:1042-1
CVE-2016-9586
CVE-2017-7407
CVE    2
CVE-2017-7407
CVE-2016-9586
CPE    4
cpe:/o:suse:suse_linux_enterprise_server:12:sp2
cpe:/a:libcurl4:libcurl4
cpe:/a:haxx:curl
cpe:/a:haxx:curl:7.53.1
...

© SecPod Technologies