Hash: SHA256

Package        : curl
Version        : 7.26.0-1+wheezy21
CVE ID         : CVE-2017-1000254
Debian Bug     : #877671

It was discovered that there was a out-of-bounds read vulnerability in
curl, a command-line and library for transferring data over HTTP/FTP,
etc. A malicious FTP server could abuse this to prevent curl-based
clients from interacting with it.

See  for more details.

For Debian 7 "Wheezy", this issue has been fixed in curl version
7.26.0-1+wheezy21.

We recommend that you upgrade your curl packages.


Regards,

- -- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org / chris-lamb.co.uk
       `-

Debian LTS: DLA-1121-1: curl security update

October 5, 2017
It was discovered that there was a out-of-bounds read vulnerability in curl, a command-line and library for transferring data over HTTP/FTP, etc

Summary

See for more details.

For Debian 7 "Wheezy", this issue has been fixed in curl version
7.26.0-1+wheezy21.

We recommend that you upgrade your curl packages.


Regards,

- --
,''`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-



Severity
Package : curl
Version : 7.26.0-1+wheezy21
CVE ID : CVE-2017-1000254
Debian Bug : #877671

Related News