• [SECURITY] [DSA 2902-1] curl security update

    From Salvatore Bonaccorso@1:229/2 to All on Sun Apr 13 10:30:02 2014
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-2902-1 [email protected] http://www.debian.org/security/ Salvatore Bonaccorso
    April 13, 2014 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : curl
    CVE ID : CVE-2014-0138 CVE-2014-0139
    Debian Bug : 742728

    Two vulnerabilities have been discovered in cURL, an URL transfer
    library. The Common Vulnerabilities and Exposures project identifies the following problems:

    CVE-2014-0138

    Steve Holme discovered that libcurl can in some circumstances re-use
    the wrong connection when asked to do transfers using other
    protocols than HTTP and FTP.

    CVE-2014-0139

    Richard Moore from Westpoint Ltd. reported that libcurl does not
    behave compliant to RFC 2828 under certain conditions and
    incorrectly validates wildcard SSL certificates containing literal
    IP addresses.

    For the oldstable distribution (squeeze), these problems have been fixed in version 7.21.0-2.1+squeeze8.

    For the stable distribution (wheezy), these problems have been fixed in
    version 7.26.0-1+wheezy9.

    For the testing distribution (jessie), these problems have been fixed in version 7.36.0-1.

    For the unstable distribution (sid), these problems have been fixed in
    version 7.36.0-1.

    We recommend that you upgrade your curl packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: http://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1

    iQIcBAEBCgAGBQJTSkcrAAoJEAVMuPMTQ89EJ/kQAI+bhYW6omGFeiXjY2dzZlJv oNrtpIiF73jwmQ35dKRbfNhl4rM1FHDoFN5TPWVN5nGdH3nxMmccsAUNFCz2R3z8 4L8qWGtJrAvwkUCYq8eVTVVlrW8G1wZgc/Eyzv2agenRgCuUl5YqqUd841ee2nGd BkDhnzASyk0iZL13FVWLj4jz7q/YUVh9+r1bS/gRKH2cGWjTgOthyUb2iPXUw37a 3/FMfTzj2n+1qbsTbTaP5HSIOX43is98PKbS0H+o11MOaeOxt2BAz1lM/Z/yGz+W eNnimJyM4dN1eUkhz8qXLkFVicBYp0ttYcUBDyQgQpE2IF29ULL4g9ZxeV0fraai EwbkoI5SYKeQFN3LQ8Q7iGqh+vyuUEkGXAGAnTrt/8xi0Gm42gMercYGHH6M/Qtq pGsaqrbMn793N8oSimiuhdbU3KN3UQo6fUYXzAqcjhnw1bdozz69ZWnuRo06j+yZ 87E8NrF+z1DkLba/e9CINAdGhFisu5LK5hS0mLLRk3MqoLIRe0AbmxsGwQRB2N3Z KGMphBKdcf/KiPRbqdTKzm7sDvjqiLuDfjxqu4BDIqZs5P/AHyETyeL6AgS2quws 0I1ufW452CdauJ00uHl7q0m2nd733bhuiHMCJ0boU+EQHJYLV0sj3U4vwGWRcIb6 8aoI57o9zT39JlGFWwbU
    =hzeM
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: https://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)