SUSE-SU-2017:2312-1
Dashboard / Vulnerabilities / SUSE-SU-2017:2312-1
SUSE-SU-2017:2312-1
Summary: Security update for curl
Details: This update for curl fixes the following issues: - CVE-2017-1000100: TFP sends more than buffer size and it could lead to a denial of service (bsc#1051644) - CVE-2017-7407: ourWriteOut function problem could lead to a heap buffer over-read (bsc#1032309) - CVE-2016-9586: libcurl printf issue could lead to buffer overflow (bsc#1015332)
References: https://www.suse.com/support/update/announcement/2017/suse-su-20172312-1/, https://bugzilla.suse.com/1015332, https://bugzilla.suse.com/1032309, https://bugzilla.suse.com/1051644, https://www.suse.com/security/cve/CVE-2016-9586, https://www.suse.com/security/cve/CVE-2017-1000100, https://www.suse.com/security/cve/CVE-2017-7407
Affected packages
Package
Name: curl
Purl: pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
