MGASA-2015-0263
Dashboard / Vulnerabilities / MGASA-2015-0263
Summary: Updated curl package fixes security vulnerability
Details: libcurl can wrongly send HTTP credentials when re-using connections. Even if the handle for an HTTP connection is reset, it retains the credentials, which can cause them to be unintentionally leaked in subsequent requests (CVE-2015-3236). libcurl can get tricked by a malicious SMB server to send off data it did not intend to. A malicious SMB server can use this to access arbitrary process memory, or to crash the client, causing a denial of service (CVE-2015-3237).
References: https://advisories.mageia.org/MGASA-2015-0263.html, https://bugs.mageia.org/show_bug.cgi?id=16140, http://curl.haxx.se/docs/adv_20150617A.html, http://curl.haxx.se/docs/adv_20150617B.html
Affected packages
Package
Name: curl
Purl: pkg:rpm/mageia/curl?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
