MGASA-2018-0054
Dashboard / Vulnerabilities / MGASA-2018-0054
MGASA-2018-0054
Summary: Updated curl packages fix security vulnerability
Details: libcurl contains a buffer overrun flaw in the NTLM authentication code (CVE-2017-8816). libcurl contains a read out of bounds flaw in the FTP wildcard function (CVE-2017-8817). libcurl may read outside of a heap allocated buffer when doing FTP (CVE-2017-1000254). libcurl contains a buffer overrun flaw in the IMAP handler (CVE-2017-1000257).
References: https://advisories.mageia.org/MGASA-2018-0054.html, https://bugs.mageia.org/show_bug.cgi?id=21819, https://curl.haxx.se/docs/adv_20171004.html, https://curl.haxx.se/docs/adv_20171023.html, https://curl.haxx.se/docs/adv_2017-12e7.html, https://curl.haxx.se/docs/adv_2017-ae72.html
Affected packages
Package
Name: curl
Purl: pkg:rpm/mageia/curl?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
