SUSE-SU-2017:1042-1
Dashboard / Vulnerabilities / SUSE-SU-2017:1042-1
SUSE-SU-2017:1042-1
Summary: Security update for curl
Details: This update for curl fixes the following issues: Security issue fixed: - CVE-2016-9586: libcurl printf floating point buffer overflow (bsc#1015332) - CVE-2017-7407: The ourWriteOut function in tool_writeout.c in curl might have allowed physically proximate attackers to obtain sensitive information from process memory in opportunistic circumstances by reading a workstation screen during use of a --write-out argument ending in a '%' character, which lead to a heap-based buffer over-read (bsc#1032309). With this release new default ciphers are active (SUSE_DEFAULT, bsc#1027712).
References: https://www.suse.com/support/update/announcement/2017/suse-su-20171042-1/, https://bugzilla.suse.com/1015332, https://bugzilla.suse.com/1027712, https://bugzilla.suse.com/1032309, https://www.suse.com/security/cve/CVE-2016-9586, https://www.suse.com/security/cve/CVE-2017-7407
Affected packages
Package
Name: curl
Purl: pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1
Affected ranges
Type: ECOSYSTEM
Events:
