• [SECURITY] [DSA 4098-1] curl security update

    From Alessandro Ghedini@1:229/2 to All on Fri Jan 26 11:10:02 2018
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4098-1 [email protected] https://www.debian.org/security/ Alessandro Ghedini January 26, 2018 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : curl
    CVE ID : CVE-2018-1000005 CVE-2018-1000007

    Two vulnerabilities were discovered in cURL, an URL transfer library.

    CVE-2018-1000005

    Zhouyihai Ding discovered an out-of-bounds read in the code
    handling HTTP/2 trailers. This issue doesn't affect the oldstable
    distribution (jessie).

    CVE-2018-1000007

    Craig de Stigter discovered that authentication data might be leaked
    to third parties when following HTTP redirects.

    For the oldstable distribution (jessie), these problems have been fixed
    in version 7.38.0-4+deb8u9.

    For the stable distribution (stretch), these problems have been fixed in version 7.52.1-5+deb9u4.

    We recommend that you upgrade your curl packages.

    For the detailed security status of curl please refer to
    its security tracker page at:
    https://security-tracker.debian.org/tracker/curl

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEBsId305pBx+F583DbwzL4CFiRygFAlpq+YMACgkQbwzL4CFi RygoCRAArQKcYRR1ay6Qbj4HHMINwJAcPo7PgtRREFjzkffKOd98SbJU+QN8MNT9 USe/OEnjRM5d7iTk5pqZBCH9wjm0KSCtq4nko1lSxnFUtjJfi1CNz2chFYKnR9/w OTG6SNzQXoxO56q2e6vYbh5CFbXbpJfuc6xUdSSjgkXWnFFXBYwB83YpouF7pTWK DFVW6ZTxt7xig8RrO7Q6+7+m2qxEW+raaDBUwgczxMTZc50uqzN+MH61QH99Jljn tRhT7/weEZV4Uiu3Q8aY8ERJsOClE8tdlT5MDp5IxQYAm8A9I4GgB+mRkh0+Z29Y J8QKg4jI7MaEGWN342HTwyiFvGjHsFqa4wQzEyMKM6PJo5Herti5xOQbPVGWnMQX dVzO+wU9lu3zitWPSdNXFV9jKHF0nrHIrTEWcTVk0L30oVe3xN3GmW/PCxKWO1JD hzNwwReQ/CUi7+4Ww9qmpcQGSvTk5uO+PdywoPs0cqP4qsPln3ENDf/4UXQdQ2pZ 7jh9rT+WJ0m/3RAX6yBQoZfSbhSJD+ZsPTrdV0fWIW9PW9c8fjXnkzIOZNeYFKxH XLyiDRtJszZ5DvSpMKZaFghaICHRlbe4sdGj7gyQ4f00ypPtEXz+LDDVD/mAK3ou d4/x0/0W6T5h4nWdMqE9k1aInKJJcVE1lJvAFqM8QqEZw5I5Vbg=
    =68U/
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)