Login
Newsletter
Werbung

Sicherheit: Preisgabe von Informationen in curl
Aktuelle Meldungen Distributionen
Name: Preisgabe von Informationen in curl
ID: USN-2399-1
Distribution: Ubuntu
Plattformen: Ubuntu 10.04 LTS, Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, Ubuntu 14.10
Datum: Di, 11. November 2014, 07:47
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3707
Applikationen: curl

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============0478878423527262316==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="1nIeqhmaXH1iD32tLuEoTH9rGdwQc2fUA"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--1nIeqhmaXH1iD32tLuEoTH9rGdwQc2fUA
Content-Type: text/plain; charset=utf-
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-2399-1
November 10, 2014

curl vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS

Summary:

curl could expose sensitive information over the network.

Software Description:
- curl: HTTP, HTTPS, and FTP client and client libraries

Details:

Symeon Paraschoudis discovered that curl incorrectly handled memory when
being used with CURLOPT_COPYPOSTFIELDS and curl_easy_duphandle(). This may
result in sensitive data being incorrectly sent to the remote server.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.10:
libcurl3 7.37.1-1ubuntu3.1
libcurl3-gnutls 7.37.1-1ubuntu3.1
libcurl3-nss 7.37.1-1ubuntu3.1

Ubuntu 14.04 LTS:
libcurl3 7.35.0-1ubuntu2.2
libcurl3-gnutls 7.35.0-1ubuntu2.2
libcurl3-nss 7.35.0-1ubuntu2.2

Ubuntu 12.04 LTS:
libcurl3 7.22.0-3ubuntu4.11
libcurl3-gnutls 7.22.0-3ubuntu4.11
libcurl3-nss 7.22.0-3ubuntu4.11

Ubuntu 10.04 LTS:
libcurl3 7.19.7-1ubuntu1.10
libcurl3-gnutls 7.19.7-1ubuntu1.10

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2399-1
CVE-2014-3707

Package Information:
https://launchpad.net/ubuntu/+source/curl/7.37.1-1ubuntu3.1
https://launchpad.net/ubuntu/+source/curl/7.35.0-1ubuntu2.2
https://launchpad.net/ubuntu/+source/curl/7.22.0-3ubuntu4.11
https://launchpad.net/ubuntu/+source/curl/7.19.7-1ubuntu1.10



--1nIeqhmaXH1iD32tLuEoTH9rGdwQc2fUA
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJUYMmYAAoJEGVp2FWnRL6TXaUP/RfRKnLRgSc2VQ2Zp6cBqGnU
GJQg5EYmhgHhy/ks5Fbd9zME9PUHi0C9LuXQ71ZS/Gw5HcoQRCvazhKn7zb5Hr09
fEsBoUTCiBMcyTXC01345XtcP1bGrZyb7eXbppvYWhwrAQcKKUNIoGCPbi+EOkcH
/OlfGnlHJzLy8/91mhg6+BNffvymMSh3IyfF0WhOT2H7H4bjBfuyqI+BkB09j5i5
dGTUJ/Zt9eK7TumyXfCo2SbwlG9MtvXeApXnRCf5yKVSRdSnHrT8gAm3hZgXXG52
77hR3MTgv7QW8rdB4ypPauJkjwYhnGVuvjyA86ZHWtXeWXTddb7Cip+O//nTE8EY
JJ0mEB3Vn6jsdriTn7vsYI7E0rZExlSajtZYbAKBNPoZcFzQElb+FoI6xtu+QK0i
lHziRgca//vKFwa7Fs7JquKmJvFPVCGfj5Od9RjnzaTIVB+fafnlQqxUgxIOGEfs
TvHTCPlH0olxH69LzVxRiNpUlzWNFyrV/zTFee69HhB61F151ntMzbbPmnyNy1I4
jn+2trFpDt+gy0sviIiaw+EYOOGpVk1npZsfQ1JXjqiJg1L4eOdTL1xcrSaSvEt/
IFtd2LfQS4AW0DU+yAv3jagERtzkmF2VMiwWsiEBzWHHmw1T2berhPkKFRRDO3hk
Tp2elQO4xZaotIGwx1ev
=VhMK
-----END PGP SIGNATURE-----

--1nIeqhmaXH1iD32tLuEoTH9rGdwQc2fUA--


--===============0478878423527262316==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============0478878423527262316==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung