shield
Security update for curl
SUSE-SLE-SERVER-12-SP1-2017-609
This update for curl fixes the following issues: Security issue fixed: - CVE-2016-9586: libcurl printf floating point buffer overflow (bsc#1015332) - CVE-2017-7407: The ourWriteOut function in tool_writeout.c in curl might have allowed physically proximate attackers to obtain sensitive information from process memory in opportunistic circumstances by reading a workstation screen during use of a --write-out argument ending in a '%' character, which lead to a heap-based buffer over-read (bsc#1032309). With this release new default ciphers are active (SUSE_DEFAULT, bsc#1027712).
-
Release DateApr 18 2017
-
References
-
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Linux Enterprise Server 12.1 ppc64le
-
Packages
SUSE Linux Enterprise Server for SAP Applications 12.1 x86_64
-
Packagescurl
A Tool for Transferring Data from URLslibcurl47.37.0-36.1 lock rpm lock src
Version 4 of cURL shared librarylibcurl4-32bit7.37.0-36.1 lock rpm
Version 4 of cURL shared library7.37.0-36.1 lock rpm
SUSE Linux Enterprise Server 12.1 s390x
-
Packagescurl
A Tool for Transferring Data from URLslibcurl47.37.0-36.1 lock rpm lock src
Version 4 of cURL shared librarylibcurl4-32bit7.37.0-36.1 lock rpm
Version 4 of cURL shared library7.37.0-36.1 lock rpm