MGASA-2015-0440
Dashboard / Vulnerabilities / MGASA-2015-0440
MGASA-2015-0440
Summary: Updated python-curl packages fix security vulnerability
Details: A use-after-free vulnerability was found in Curl object's HTTPPOST setopt when a Unicode value is passed as a value with a FORM_BUFFERPTR. The str object created from the passed in unicode object would have its buffer used but the unicode object would be stored instead of the str object (rhbz#1277488).
References: https://advisories.mageia.org/MGASA-2015-0440.html, https://bugs.mageia.org/show_bug.cgi?id=17077, http://openwall.com/lists/oss-security/2015/11/03/4, https://lists.fedoraproject.org/pipermail/package-announce/2015-November/170967.html
Affected packages
Package
Name: python-curl
Purl: pkg:rpm/mageia/python-curl?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
