gpp_maybe
Security update for curl
SUSE-SLE-SAP-12-SP4-2022-2813
This update for curl fixes the following issues: - CVE-2022-27781: Fixed an issue where curl will get stuck in an infinite loop when trying to retrieve details about a TLS server's certificate chain (bnc#1199223). - CVE-2022-27782: Fixed an issue where TLS and SSH connections would be reused even when a related option had been changed (bsc#1199224). - CVE-2022-32206: Fixed an uncontrolled memory consumption issue caused by an unbounded number of compression layers (bsc#1200735). - CVE-2022-32208: Fixed an incorrect message verification issue when performing FTP transfers using krb5 (bsc#1200737).
-
Release DateAug 16 2022
-
ReferencesBugzilla: 1199223, 1199224, 1200735, 1200737
CVEs: CVE-2022-27781, CVE-2022-27782, CVE-2022-32206, CVE-2022-32208 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Server for SAP Applications 12.4 ppc64le
-
Packages
SUSE Linux Enterprise Server for SAP Applications 12.4 x86_64
-
Packagescurl
A Tool for Transferring Data from URLslibcurl47.60.0-4.38.1lock rpmlock src
Version 4 of cURL shared librarylibcurl4-32bit7.60.0-4.38.1lock rpm
Version 4 of cURL shared library7.60.0-4.38.1lock rpm