SUSE-SU-2017:1043-1
Dashboard / Vulnerabilities / SUSE-SU-2017:1043-1
SUSE-SU-2017:1043-1
Summary: Security update for curl
Details: This update for curl fixes the following issues: These security issues were fixed: - CVE-2016-9586: libcurl printf floating point buffer overflow (bsc#1015332) - CVE-2017-7407: The ourWriteOut function in tool_writeout.c in curl might have allowed physically proximate attackers to obtain sensitive information from process memory in opportunistic circumstances by reading a workstation screen during use of a --write-out argument ending in a '%' character, which lead to a heap-based buffer over-read (bsc#1032309).
References: https://www.suse.com/support/update/announcement/2017/suse-su-20171043-1/, https://bugzilla.suse.com/1015332, https://bugzilla.suse.com/1032309, https://www.suse.com/security/cve/CVE-2016-9586, https://www.suse.com/security/cve/CVE-2017-7407
Affected packages
Package
Name: curl
Purl: pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
