• [SECURITY] [DSA 2798-2] curl security update

    From Salvatore Bonaccorso@1:229/2 to All on Wed Nov 20 23:20:01 2013
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-2798-2 [email protected] http://www.debian.org/security/ Salvatore Bonaccorso November 20, 2013 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : curl
    Vulnerability : unchecked ssl certificate host name
    Problem type : remote
    Debian-specific: no
    CVE ID : CVE-2013-4545

    The update for curl in DSA-2798-1 uncovered a regression affecting the
    curl command line tool behaviour (#729965). This update disables host verification too when using the --insecure option.

    For the oldstable distribution (squeeze), this problem has been fixed in version 7.21.0-2.1+squeeze6.

    For the stable distribution (wheezy), this problem has been fixed in
    version 7.26.0-1+wheezy6.

    For the testing (jessie) and unstable (sid) distributions, the curl
    command line tool behaves as expected with the --insecure option.

    For reference the original advisory text follows.

    Scott Cantor discovered that curl, a file retrieval tool, would disable
    the CURLOPT_SSLVERIFYHOST check when the CURLOPT_SSL_VERIFYPEER setting
    was disabled. This would also disable ssl certificate host name checks
    when it should have only disabled verification of the certificate trust
    chain.

    The default configuration for the curl package is not affected by this
    issue since CURLOPT_SSLVERIFYPEER is enabled by default.

    For the oldstable distribution (squeeze), this problem has been fixed in version 7.21.0-2.1+squeeze5.

    For the stable distribution (wheezy), this problem has been fixed in
    version 7.26.0-1+wheezy5.

    For the testing (jessie) and unstable (sid) distributions, this problem
    has been fixed in version 7.33.0-1.

    We recommend that you upgrade your curl packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: http://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.15 (GNU/Linux)

    iQIcBAEBCgAGBQJSjTSeAAoJEAVMuPMTQ89E+bMP/jxYqQsDtXJxFvefUBDI4Mki 3j6l+WsSd+GhEx/Sp7CYpUYmNjfybYZl2MdXeOfyB3czF3saBhpEo4/wXeLEJuQD PjA52GRvnfE4/pDnAIcHhbkfrI2MSJMU+NUpC2d2Zy2YAgQoeSBftSb91xZ9B1SI jbuiKNrSgIgcusBSmNFCXb4TdkCVhGi37B7J7NO9rPR6n6yBvX1xsIEJYOGJeMxL S9OWwbmcwjCdN6feNVK99YgfmEmRGLTpMosAmJSNN4KXa+OSr+g9Y+NHkve+CYy/ GmKX/MInXaWdcRk4LoyEdQ8idhWdJEdPe7ZEoLttSGnfLUyXBzTVKbK5Ugx6RYM8 1NbKYZVGYfQAOwjIbKgGn0F5eQDi+OiXh1JleyLa7y8pvk+7tq6pOKAsa9H2rDsn nVTVzOs6qIDdjESndLEUNG+JJJpkpB/MOAfdAx4KHKS7GQ+quMg99azUdSmDRFbC EN8XA8JrC0LOSeUJiiZTdRgOpjlTKgXUHKrr9Z0Ft/U/uWxK9pX5nTcaw/WwI+vQ Ms7yx0i0WrTvGkTXLHx+JeGrPcvjNxX8muTEq07ZkceDjZIefmZs0J139Xd+OSn1 M506eYcVgf4WNj8swR0h20S8eTA0BsNxXVOHmn113bwd95GxaTM4pKtANHuKLV3l Jq399e4/SnX3FWtSPFuK
    =v0Ra
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: http://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • From Johannes Stummer@1:229/2 to All on Wed Nov 20 23:40:01 2013
    XPost: linux.debian.security
    From: [email protected]

    --047d7b5d45d001519704eba332fa
    Content-Type: text/plain; charset=ISO-8859-1

    Fyinfo archivar php dev
    Am 20.11.2013 23:18 schrieb "Salvatore Bonaccorso" <[email protected]>:

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-2798-2 [email protected] http://www.debian.org/security/ Salvatore Bonaccorso November 20, 2013 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : curl
    Vulnerability : unchecked ssl certificate host name
    Problem type : remote
    Debian-specific: no
    CVE ID : CVE-2013-4545

    The update for curl in DSA-2798-1 uncovered a regression affecting the
    curl command line tool behaviour (#729965). This update disables host verification too when using the --insecure option.

    For the oldstable distribution (squeeze), this problem has been fixed in version 7.21.0-2.1+squeeze6.

    For the stable distribution (wheezy), this problem has been fixed in
    version 7.26.0-1+wheezy6.

    For the testing (jessie) and unstable (sid) distributions, the curl
    command line tool behaves as expected with the --insecure option.

    For reference the original advisory text follows.

    Scott Cantor discovered that curl, a file retrieval tool, would disable
    the CURLOPT_SSLVERIFYHOST check when the CURLOPT_SSL_VERIFYPEER setting
    was disabled. This would also disable ssl certificate host name checks
    when it should have only disabled verification of the certificate trust chain.

    The default configuration for the curl package is not affected by this
    issue since CURLOPT_SSLVERIFYPEER is enabled by default.

    For the oldstable distribution (squeeze), this problem has been fixed in version 7.21.0-2.1+squeeze5.

    For the stable distribution (wheezy), this problem has been fixed in
    version 7.26.0-1+wheezy5.

    For the testing (jessie) and unstable (sid) distributions, this problem
    has been fixed in version 7.33.0-1.

    We recommend that you upgrade your curl packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: http://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.15 (GNU/Linux)

    iQIcBAEBCgAGBQJSjTSeAAoJEAVMuPMTQ89E+bMP/jxYqQsDtXJxFvefUBDI4Mki 3j6l+WsSd+GhEx/Sp7CYpUYmNjfybYZl2MdXeOfyB3czF3saBhpEo4/wXeLEJuQD PjA52GRvnfE4/pDnAIcHhbkfrI2MSJMU+NUpC2d2Zy2YAgQoeSBftSb91xZ9B1SI jbuiKNrSgIgcusBSmNFCXb4TdkCVhGi37B7J7NO9rPR6n6yBvX1xsIEJYOGJeMxL S9OWwbmcwjCdN6feNVK99YgfmEmRGLTpMosAmJSNN4KXa+OSr+g9Y+NHkve+CYy/ GmKX/MInXaWdcRk4LoyEdQ8idhWdJEdPe7ZEoLttSGnfLUyXBzTVKbK5Ugx6RYM8 1NbKYZVGYfQAOwjIbKgGn0F5eQDi+OiXh1JleyLa7y8pvk+7tq6pOKAsa9H2rDsn nVTVzOs6qIDdjESndLEUNG+JJJpkpB/MOAfdAx4KHKS7GQ+quMg99azUdSmDRFbC EN8XA8JrC0LOSeUJiiZTdRgOpjlTKgXUHKrr9Z0Ft/U/uWxK9pX5nTcaw/WwI+vQ Ms7yx0i0WrTvGkTXLHx+JeGrPcvjNxX8muTEq07ZkceDjZIefmZs0J139Xd+OSn1 M506eYcVgf4WNj8swR0h20S8eTA0BsNxXVOHmn113bwd95GxaTM4pKtANHuKLV3l Jq399e4/SnX3FWtSPFuK
    =v0Ra
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected] with a subject of "unsubscribe". Trouble? Contact
    [email protected]
    Archive: http://lists.debian.org/[email protected]



    --047d7b5d45d001519704eba332fa
    Content-Type: text/html; charset=ISO-8859-1
    Content-Transfer-Encoding: quoted-printable

    <p dir="ltr">Fyinfo archivar php dev</p>
    <div class="gmail_quote">Am 20.11.2013 23:18 schrieb &quot;Salvatore Bonaccorso&quot; &lt;<a href="mailto:[email protected]">[email protected]</a>&gt;:<br type="attribution"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc
    solid;padding-left:1ex">
    -----BEGIN PGP SIGNED MESSAGE-----<br>
    Hash: SHA512<br>

    - -------------------------------------------------------------------------<br> Debian Security Advisory DSA-2798-2 � � � � � � � � � <a href="mailto:[email protected]">[email protected]</a><br>
    <a href="http://www.debian.org/security/" target="_blank">http://www.debian.org/security/</a> � � � � � � � � � � �Salvatore Bonaccorso<br>
    November 20, 2013 � � � � � � � � � � �<a href="http://www.debian.org/security/faq" target="_blank">http://www.debian.org/security/faq</a><br>
    - -------------------------------------------------------------------------<br>

    Package � � � �: curl<br>
    Vulnerability �: unchecked ssl certificate host name<br>
    Problem type � : remote<br>
    Debian-specific: no<br>
    CVE ID � � � � : CVE-2013-4545<br>

    The update for curl in DSA-2798-1 uncovered a regression affecting the<br>
    curl command line tool behaviour (#729965). This update disables host<br> verification too when using the --insecure option.<br>

    For the oldstable distribution (squeeze), this problem has been fixed in<br> version <a href="tel:7.21.0-2.1" value="+43721021">7.21.0-2.1</a>+squeeze6.<br>

    For the stable distribution (wheezy), this problem has been fixed in<br> version 7.26.0-1+wheezy6.<br>


    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)