Login
Newsletter
Werbung

Sicherheit: Ausführen beliebiger Kommandos in curl
Aktuelle Meldungen Distributionen
Name: Ausführen beliebiger Kommandos in curl
ID: USN-1346-1
Distribution: Ubuntu
Plattformen: Ubuntu 10.10, Ubuntu 11.04, Ubuntu 11.10
Datum: Di, 24. Januar 2012, 23:32
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0036
Applikationen: curl

Originalnachricht


--===============4402193513228667122==
Content-Type: multipart/signed; micalg="pgp-sha512";
protocol="application/pgp-signature";
boundary="=-fPf1osFBPycPohHVMycf"


--=-fPf1osFBPycPohHVMycf
Content-Type: text/plain; charset="UTF-8
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1346-1
January 24, 2012

curl vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.10

Summary:

curl could be tricked into injecting arbitrary data if it handled a
malicious URL.

Software Description:
- curl: HTTP, HTTPS, and FTP client and client libraries

Details:

Dan Fandrich discovered that curl incorrectly handled URLs containing
embedded or percent-encoded control characters. If a user or automated
system were tricked into processing a specially crafted URL, arbitrary
data could be injected.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
libcurl3 7.21.6-3ubuntu3.2
libcurl3-gnutls 7.21.6-3ubuntu3.2
libcurl3-nss 7.21.6-3ubuntu3.2

Ubuntu 11.04:
libcurl3 7.21.3-1ubuntu1.5
libcurl3-gnutls 7.21.3-1ubuntu1.5
libcurl3-nss 7.21.3-1ubuntu1.5

Ubuntu 10.10:
libcurl3 7.21.0-1ubuntu1.3
libcurl3-gnutls 7.21.0-1ubuntu1.3

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1346-1
CVE-2012-0036

Package Information:
https://launchpad.net/ubuntu/+source/curl/7.21.6-3ubuntu3.2
https://launchpad.net/ubuntu/+source/curl/7.21.3-1ubuntu1.5
https://launchpad.net/ubuntu/+source/curl/7.21.0-1ubuntu1.3



--ßPf1osFBPycPohHVMycf
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part
Content-Transfer-Encoding: 7bit

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAABCgAGBQJPHyIjAAoJEGVp2FWnRL6TnocP/0NZ0l33jTPwUHtoKl1NNDUv
+0o4hbD3HUHGbIV9/wzTBqDQTDkqFgoNUbLBcBkgsOqyuwIPOcIdZAp3BJa/XifJ
ZJcSz8wyeNxWr4zvnJcce9Yx/QCmPi2cRmebTbgbFnlEFnFNcK9MzzaQFzLp5RzU
zZDueWneoGc+Px2TmCR/KuqG07jmHl8Um2nywumerhfKmFZN/VogN56YNIOebDmr
vh9/RzCz/pMlwUttxcF4Xc1OjpRzhL2IyC10LzhAKUSt2vRUh2UsYT3A4MEoc/9F
X5HvOpV8tpLh7dmkPkUyhXyXJUDcGT8oHW650yt4HNyqtzvRHx9ZwGLEJkycBdtk
QacYgwa6hXT802iI/7fD2WHUUjgEX6UTXFZ4YUZc7xu+1ZXb0Cf+tz2OPtYLJee9
Qe1Fjhb5QNTFspY5OK3fK4wMlC8/WiAnR/mTFFjDfJrM6968axDATl+NhUOcxgUn
BBMJUkODZigc+HhkPrJ4bDrBYzej/h1QKlYVG+qALGUuaumzwT1s/V0qtNtgqWVm
oSfwL0c/5OEeoS563SHe/cNZIMlVsylKxqeaxo+9L+fJLEZ71ARGDPCyDCbYt8gE
lsBbHTI1WB6eHnVM2ny4YfHUCc0zFt8oWCEK+Rl/6Bp3QqtaFpls3gF+LBcS+4s0
1+rR8M9M9cS4OkaKPYJD
=cyW9
-----END PGP SIGNATURE-----

--=-fPf1osFBPycPohHVMycf--



--===============4402193513228667122==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============4402193513228667122==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung