Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

curl: security update to 7.65.0 #1852

Closed
6 tasks done
l2dy opened this issue May 27, 2019 · 1 comment
Closed
6 tasks done

curl: security update to 7.65.0 #1852

l2dy opened this issue May 27, 2019 · 1 comment
Assignees
Labels
security Topic/issue involves a security issue/fixed upgrade Topic/issue involves a package upgrade

Comments

@l2dy
Copy link
Member

l2dy commented May 27, 2019

CVE IDs: CVE-2019-5435 (32-bit only), CVE-2019-5436

Other security advisory IDs: USN-3993-1

Descriptions:
Wenchao Li discovered that curl incorrectly handled memory in the
curl_url_set() function. A remote attacker could use this issue to cause
curl to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 19.04. (CVE-2019-5435)

It was discovered that curl incorrectly handled memory when receiving data
from a TFTP server. A remote attacker could use this issue to cause curl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2019-5436)

Architectural progress:

  • AMD64 amd64
    • 32-bit Optional Environment optenv32
  • AArch64 arm64
  • ARMv7 armel
  • PowerPC 64-bit BE ppc64
  • PowerPC 32-bit BE powerpc
@l2dy l2dy added upgrade Topic/issue involves a package upgrade security Topic/issue involves a security issue/fixed to-stable labels May 27, 2019
@KexyBiscuit KexyBiscuit self-assigned this May 28, 2019
@KexyBiscuit KexyBiscuit added this to the Winter 2018 milestone May 28, 2019
MingcongBai added a commit that referenced this issue Jul 9, 2019
@KexyBiscuit
Copy link
Member

Use AOSA-2019-0186.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Topic/issue involves a security issue/fixed upgrade Topic/issue involves a package upgrade
Projects
None yet
Development

No branches or pull requests

2 participants