gpp_maybe
Security update for curl
SUSE-SLE-SERVER-12-SP1-2016-1591
This update for curl fixes the following security issues: - CVE-2016-8624: invalid URL parsing with '#' (bsc#1005646) - CVE-2016-8623: Use-after-free via shared cookies (bsc#1005645) - CVE-2016-8622: URL unescape heap overflow via integer truncation (bsc#1005643) - CVE-2016-8621: curl_getdate read out of bounds (bsc#1005642) - CVE-2016-8620: glob parser write/read out of bounds (bsc#1005640) - CVE-2016-8619: double-free in krb5 code (bsc#1005638) - CVE-2016-8618: double-free in curl_maprintf (bsc#1005637) - CVE-2016-8617: OOB write via unchecked multiplication (bsc#1005635) - CVE-2016-8616: case insensitive password comparison (bsc#1005634) - CVE-2016-8615: cookie injection for other servers (bsc#1005633) - CVE-2016-7167: escape and unescape integer overflows (bsc#998760)
-
Release DateNov 2 2016
-
ReferencesBugzilla: 1005646, 1005645, 1005643, 1005642, 1005640, 1005633, 998760, 1005634, 1005635, 1005638, 1005637
CVEs: CVE-2016-8618, CVE-2016-8619, CVE-2016-7167, CVE-2016-8615, CVE-2016-8616, CVE-2016-8617, CVE-2016-8621, CVE-2016-8620, CVE-2016-8623, CVE-2016-8622, CVE-2016-8624 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Server 12.1 ppc64le
-
Packages
SUSE Linux Enterprise Server 12.1 s390x
-
Packagescurl
A Tool for Transferring Data from URLslibcurl47.37.0-31.1 lock rpm lock src
Version 4 of cURL shared librarylibcurl4-32bit7.37.0-31.1 lock rpm
Version 4 of cURL shared library7.37.0-31.1 lock rpm
SUSE Linux Enterprise Server for SAP Applications 12.1 x86_64
-
Packagescurl
A Tool for Transferring Data from URLslibcurl47.37.0-31.1 lock rpm lock src
Version 4 of cURL shared librarylibcurl4-32bit7.37.0-31.1 lock rpm
Version 4 of cURL shared library7.37.0-31.1 lock rpm