MGASA-2024-0099
Dashboard / Vulnerabilities / MGASA-2024-0099
MGASA-2024-0099
Summary: Updated curl packages fix security vulnerabilities
Details: CVE-2024-2004: Usage of disabled protocol If all protocols are disabled at run-time with none being added, curl/libcurl would still allow communication with the default set of allowed protocols, including some that are unencrypted. CVE-2024-2398: HTTP/2 push headers memory-leak A memory leak could occur when an application enabled HTTP/2 server push and the server sent a large number of headers.
References: https://advisories.mageia.org/MGASA-2024-0099.html, https://bugs.mageia.org/show_bug.cgi?id=33020, https://curl.se/docs/CVE-2024-2004.html, https://curl.se/docs/CVE-2024-2398.html
Affected packages
Package
Name: curl
Purl: pkg:rpm/mageia/curl?arch=source&distro=mageia-9
Affected ranges
Type: ECOSYSTEM
Events:
