shield Security update for curl
SUSE-SLE-SERVER-12-SP1-2017-609


This update for curl fixes the following issues: Security issue fixed: - CVE-2016-9586: libcurl printf floating point buffer overflow (bsc#1015332) - CVE-2017-7407: The ourWriteOut function in tool_writeout.c in curl might have allowed physically proximate attackers to obtain sensitive information from process memory in opportunistic circumstances by reading a workstation screen during use of a --write-out argument ending in a '%' character, which lead to a heap-based buffer over-read (bsc#1032309). With this release new default ciphers are active (SUSE_DEFAULT, bsc#1027712).


cloud_download Downloads

SUSE Linux Enterprise Server 12.1 ppc64le
  • Packages
    curl
    A Tool for Transferring Data from URLs
    7.37.0-36.1 lock rpm lock src
    libcurl4
    Version 4 of cURL shared library
    7.37.0-36.1 lock rpm
SUSE Linux Enterprise Server for SAP Applications 12.1 x86_64
  • Packages
    curl
    A Tool for Transferring Data from URLs
    7.37.0-36.1 lock rpm lock src
    libcurl4
    Version 4 of cURL shared library
    7.37.0-36.1 lock rpm
    libcurl4-32bit
    Version 4 of cURL shared library
    7.37.0-36.1 lock rpm
SUSE Linux Enterprise Server 12.1 s390x
  • Packages
    curl
    A Tool for Transferring Data from URLs
    7.37.0-36.1 lock rpm lock src
    libcurl4
    Version 4 of cURL shared library
    7.37.0-36.1 lock rpm
    libcurl4-32bit
    Version 4 of cURL shared library
    7.37.0-36.1 lock rpm