Mageia 2018-0423: curl security update
Summary
Updated curl packages fix security vulnerabilities:
Peter Wu discovered that curl incorrectly handled certain SMTP buffers. A
remote attacker could use this issue to cause curl to crash, resulting in
a denial of service, or possibly execute arbitrary code (CVE-2018-0500).
Zhaoyang Wu discovered that cURL, an URL transfer library, contains a buffer
overflow in the NTLM authentication code triggered by passwords that exceed
2GB in length on 32bit systems (CVE-2018-14618).
Phan Thanh discovered that curl incorrectly handled certain FTP paths.
An attacker could use this to cause a denial of service or possibly
execute arbitrary code (CVE-2018-1000120).
Dario Weisser discovered that curl incorrectly handled certain LDAP URLs.
An attacker could possibly use this issue to cause a denial of service
(CVE-2018-1000121).
Max Dymond discovered that curl incorrectly handled certain RTSP data. An
attacker could possibly use this to cause a denial of service or even to
get access to sensitive data...
References
- https://bugs.mageia.org/show_bug.cgi?id=22772
- https://curl.se/docs/CVE-2018-1000120.html
- https://curl.se/docs/CVE-2018-1000121.html
- https://curl.se/docs/CVE-2018-1000122.html
- https://curl.se/docs/CVE-2018-1000300.html
- https://curl.se/docs/CVE-2018-1000301.html
- https://curl.se/docs/CVE-2018-0500.html
- https://curl.se/docs/CVE-2018-14618.html
- https://ubuntu.com/security/notices/USN-3598-1
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/DOHQJ7DDUE5U4L6FHSUVPFQ7TAZLWSMI/
- https://ubuntu.com/security/notices/USN-3710-1
- https://www.debian.org/security/2018/dsa-4286
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0500
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14618
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000120
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000121
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000122
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000300
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000301
Resolution
MGASA-2018-0423 - Updated curl packages fix security vulnerabilities
SRPMS
- 6/core/curl-7.54.1-2.7.mga6