You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa curl

Sigurnosni nedostaci programskog paketa curl

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-4129-1
September 11, 2019

curl vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 19.04
– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in curl.

Software Description:
– curl: HTTP, HTTPS, and FTP client and client libraries

Details:

Thomas Vegas discovered that curl incorrectly handled memory when using
Kerberos over FTP. A remote attacker could use this issue to crash curl,
resulting in a denial of service. (CVE-2019-5481)

Thomas Vegas discovered that curl incorrectly handled memory during TFTP
transfers. A remote attacker could use this issue to crash curl, resulting
in a denial of service, or possibly execute arbitrary code. (CVE-2019-5482)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.04:
curl 7.64.0-2ubuntu1.2
libcurl3-gnutls 7.64.0-2ubuntu1.2
libcurl3-nss 7.64.0-2ubuntu1.2
libcurl4 7.64.0-2ubuntu1.2

Ubuntu 18.04 LTS:
curl 7.58.0-2ubuntu3.8
libcurl3-gnutls 7.58.0-2ubuntu3.8
libcurl3-nss 7.58.0-2ubuntu3.8
libcurl4 7.58.0-2ubuntu3.8

Ubuntu 16.04 LTS:
curl 7.47.0-1ubuntu2.14
libcurl3 7.47.0-1ubuntu2.14
libcurl3-gnutls 7.47.0-1ubuntu2.14
libcurl3-nss 7.47.0-1ubuntu2.14

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4129-1
CVE-2019-5481, CVE-2019-5482

Package Information:
https://launchpad.net/ubuntu/+source/curl/7.64.0-2ubuntu1.2
https://launchpad.net/ubuntu/+source/curl/7.58.0-2ubuntu3.8
https://launchpad.net/ubuntu/+source/curl/7.47.0-1ubuntu2.14
—–BEGIN PGP SIGNATURE—–

iQEzBAEBCgAdFiEEiOlTC8vdwgBRe16w9JjS2d59rZwFAl141vUACgkQ9JjS2d59
rZyaBAf/SSvoaqWbAAe37f+LdrKyDfURUkAM3y00aAibjrb9o+gBjImskA55zQgc
G+Y1afTuKUPPyLfJ0lhipm9t/lAOHzAUndlREQcVDCe/5RiXmlJVeJDALFzA5lZb
EP16n7SWkHnXG/MFIactKEJUgoNU1w2MBQWpoT4iJ6QyM+Mt3FNqI6xP6h7QKRBK
IcoqZfcKO+6o1ayEd18RKMQlkq3/6bznh95axzmiDrHvv9DKkYNkL6S5Z5ueCvQa
O3ftie7EFVqHTxPAAjikzOO5EwUWDCAKwyio0Lp6pzTdfrT51UvMgofBaQdcYGYi
4rr4mFqbbv1WcWszsVLlLyAEVH+Vww==
=3Xs7
—–END PGP SIGNATURE——-

AutorZvonimir Bosnjak
Cert idNCERT-REF-2019-09-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Nadogradnja za Microsoft Windows

Microsoft je izdao nadogradnju za otklanjanje ranjivosti peracijskom sustavu Microsoft Windows. Otkriveni nedostaci potencijalnim napadačima omogućuju izvršavanje proizvoljnog programskog koda,...

Close