[El-errata] ELSA-2019-1880 Low: Oracle Linux 7 curl security and bug fix update
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Tue Jul 30 14:41:01 PDT 2019
Oracle Linux Security Advisory ELSA-2019-1880
http://linux.oracle.com/errata/ELSA-2019-1880.html
The following updated rpms for Oracle Linux 7 have been uploaded to the
Unbreakable Linux Network:
x86_64:
curl-7.29.0-51.0.1.el7_6.3.x86_64.rpm
libcurl-7.29.0-51.0.1.el7_6.3.i686.rpm
libcurl-7.29.0-51.0.1.el7_6.3.x86_64.rpm
libcurl-devel-7.29.0-51.0.1.el7_6.3.i686.rpm
libcurl-devel-7.29.0-51.0.1.el7_6.3.x86_64.rpm
SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/curl-7.29.0-51.0.1.el7_6.3.src.rpm
Description of changes:
[7.29.0-51.0.1.el7_6.3]
- Security Fixes [OraBug: 28939992]
- CVE-2016-8615 cookie injection for other servers
(https://curl.haxx.se/docs/CVE-2016-8615.html)
- CVE-2016-8616 case insensitive password comparison
(https://curl.haxx.se/docs/CVE-2016-8616.html)
- CVE-2016-8617 OOB write via unchecked multiplication
(https://curl.haxx.se/docs/CVE-2016-8617.html)
- CVE-2016-8618 double-free in curl_maprintf
(https://curl.haxx.se/docs/CVE-2016-8618.html)
- CVE-2016-8619 double-free in krb5 code
(https://curl.haxx.se/docs/CVE-2016-8619.html)
- CVE-2016-8621 curl_getdate read out of bounds
(https://curl.haxx.se/docs/CVE-2016-8621.html)
- CVE-2016-8622 URL unescape heap overflow via integer truncation
(https://curl.haxx.se/docs/CVE-2016-8622.html)
- CVE-2016-8623 Use-after-free via shared cookies
(https://curl.haxx.se/docs/CVE-2016-8623.html)
- CVE-2016-8624 invalid URL parsing with #
(https://curl.haxx.se/docs/CVE-2016-8624.html)
[7.29.0-51.el7_6.3]
- fix NTLM password overflow via integer overflow (CVE-2018-14618)
[7.29.0-51.el7_6.2]
- prevent curl --rate-limit from crashing on https URLs (#1683292)
[7.29.0-51.el7_6.1]
- prevent curl --rate-limit from hanging on file URLs (#1281969)
More information about the El-errata
mailing list