SUSE-SU-2018:0214-1
Dashboard / Vulnerabilities / SUSE-SU-2018:0214-1
SUSE-SU-2018:0214-1
Summary: Security update for curl
Details: This update for curl fixes several issues. These security issues were fixed: - CVE-2017-1000254: Fix FTP PWD response parser out of bounds read (bsc#1061876). - CVE-2018-1000007: Prevent leaking authentication data to third parties when following redirects (bsc#1077001) Also the following adjustment was made: - Set DEFAULT_SUSE as the default cipher list (bsc#1027712)
References: https://www.suse.com/support/update/announcement/2018/suse-su-20180214-1/, https://bugzilla.suse.com/1027712, https://bugzilla.suse.com/1061876, https://bugzilla.suse.com/1077001, https://www.suse.com/security/cve/CVE-2017-1000254, https://www.suse.com/security/cve/CVE-2018-1000007
Affected packages
Package
Name: curl
Purl: pkg:rpm/suse/curl&distro=SUSE%20Studio%20Onsite%201.3
Affected ranges
Type: ECOSYSTEM
Events:
