Mehrere Probleme in curl (Aktualisierung)
ID: | USN-3805-2 |
Distribution: | Ubuntu |
Plattformen: | Ubuntu 12.04 ESM |
Datum: | Do, 1. November 2018, 22:34 |
Referenzen: | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16842 |
Applikationen: | curl |
Update von: | Mehrere Probleme in curl |
Originalnachricht |
|
--===============7701167918625334979== Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="=-yZ2fYWHeWksrxfLJIQZP" --=-yZ2fYWHeWksrxfLJIQZP Content-Type: text/plain; charset="UTF-8 Content-Transfer-Encoding: quoted-printable ========================================================================== Ubuntu Security Notice USN-3805-2 November 01, 2018 curl vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 ESM Summary: Several security issues were fixed in curl. Software Description: - curl: HTTP, HTTPS, and FTP client and client libraries Details: USN-3805-1 fixed a vulnerability in curl. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: Brian Carpenter discovered that the curl command-line tool incorrectly handled error messages. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2018-16842) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM: curl 7.22.0-3ubuntu4.24 libcurl3 7.22.0-3ubuntu4.24 libcurl3-gnutls 7.22.0-3ubuntu4.24 libcurl3-nss 7.22.0-3ubuntu4.24 In general, a standard system update will make all the necessary changes. References: https://usn.ubuntu.com/usn/usn-3805-2 https://usn.ubuntu.com/usn/usn-3805-1 CVE-2018-16842 --=-yZ2fYWHeWksrxfLJIQZP Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part Content-Transfer-Encoding: 7bit -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAABCAAGBQJb2zYbAAoJEEW851uECx9pZKcQAImsXEZABsZ2eizwxLxVa8Fs X0fh18o6FYPO/gDgUqVdGYxbU7Sfff2PdKRTrTlWFsXliw/3LzD9cBJnIq10NukC uLaOOehcDZGrPS6kxXBXql87TLmDwCWxLMQJDVLdXFDMuBTW6iRhQzby0kAJkOwp GAwLqml1IDYeIawnjCj5MZuORqCE9J88wO3xz21eHO23FA/uLcZQ3a9ldeph1A6y mpFjGkS534usbPxk1OmLqdaBmPsG0r1jJJDHqywisp6stapmHdGtNsvhRGbX8Zs0 l6YdiIzXUbLbPni+hKzqbKijIPeZrdVejhmNuknUxujB+qNVtB41EMoEmFVMMT8u kZcBuizxP31nmg7ZroVdiV3uILX5BlTqMNg6N8HwKEBu+r/ihxkrP4mzu/FdepZN Bp8RVE+i0kiiSGlRmbgxmGVHZWvofZ7vhfK6bgJ26rW1nQW4vHwPhjsTJKMf31AE YuEbs4ma56JwdU2Ck/9lk44uRKpAjkhjbc3mpJr/hgFJ1MAa+tipcp/tkGHt+7w0 wYkXco3juPNkBrlikdr3pgHRJasmx8cBExxAAyXUQJiP7rvMYKS6LQBQE4F9vMXL 8n+/CxBRtx01aOAIhpsR26PNb4ftva/ElNYyM+WhC+fmWI320gAG+283XLPY86JY 1YlqAIMvyDPeTawVxODh =Z7IY -----END PGP SIGNATURE----- --=-yZ2fYWHeWksrxfLJIQZP-- --===============7701167918625334979== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5 LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj dXJpdHktYW5ub3VuY2UK --===============7701167918625334979==-- |