[El-errata] ELBA-2019-4253 Oracle Linux 6 curl bug fix update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Wed Dec 18 08:43:11 PST 2019


Oracle Linux Bug Fix Advisory ELBA-2019-4253

http://linux.oracle.com/errata/ELBA-2019-4253.html

The following updated rpms for Oracle Linux 6 have been uploaded to the 
Unbreakable Linux Network:

i386:
curl-7.19.7-54.0.1.el6_10.i686.rpm
libcurl-7.19.7-54.0.1.el6_10.i686.rpm
libcurl-devel-7.19.7-54.0.1.el6_10.i686.rpm

x86_64:
curl-7.19.7-54.0.1.el6_10.x86_64.rpm
libcurl-7.19.7-54.0.1.el6_10.i686.rpm
libcurl-7.19.7-54.0.1.el6_10.x86_64.rpm
libcurl-devel-7.19.7-54.0.1.el6_10.i686.rpm
libcurl-devel-7.19.7-54.0.1.el6_10.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol6/SRPMS-updates/curl-7.19.7-54.0.1.el6_10.src.rpm



Description of changes:

[7.19.7-54.0.1]
- Security Fixes [OraBug: 28939992]
- CVE-2016-8615 cookie injection for other servers 
(https://curl.haxx.se/docs/CVE-2016-8615.html)
- CVE-2016-8616 case insensitive password comparison 
(https://curl.haxx.se/docs/CVE-2016-8616.html)
- CVE-2016-8617 OOB write via unchecked multiplication 
(https://curl.haxx.se/docs/CVE-2016-8617.html)
- CVE-2016-8618 double-free in curl_maprintf 
(https://curl.haxx.se/docs/CVE-2016-8618.html)
- CVE-2016-8619 double-free in krb5 code 
(https://curl.haxx.se/docs/CVE-2016-8619.html)
- CVE-2016-8621 curl_getdate read out of bounds 
(https://curl.haxx.se/docs/CVE-2016-8621.html)
- CVE-2016-8623 Use-after-free via shared cookies 
(https://curl.haxx.se/docs/CVE-2016-8623.html)
- CVE-2016-8624 invalid URL parsing with # 
(https://curl.haxx.se/docs/CVE-2016-8624.html)
- use PK11_CreateManagedGenericObject in libcurl to prevent memory leak 
[orabug 28666473]

[7.19.7-54]
- fix auth failure with duplicated WWW-Authenticate header (#1757643)





More information about the El-errata mailing list