Security update for curl
This update for curl fixes the following issues: - CVE-2020-8286: Fixed improper OSCP verification in the client side (bsc#1179593). - CVE-2020-8285: Fixed a stack overflow due to FTP wildcard (bsc#1179399). - CVE-2020-8284: Fixed an issue where a malicius FTP server could make curl connect to a different IP (bsc#1179398). This update was imported from the SUSE:SLE-15:Update update project.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for curl fixes the following issues: - CVE-2020-8286: Fixed improper OSCP verification in the client side (bsc#1179593). - CVE-2020-8285: Fixed a stack overflow due to FTP wildcard (bsc#1179399). - CVE-2020-8284: Fixed an issue where a malicius FTP server could make curl connect to a different IP (bsc#1179398). This update was imported from the SUSE:SLE-15:Update update project.
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1179398
- https://bugzilla.suse.com/1179399
- https://bugzilla.suse.com/1179593
- https://lists.opensuse.org/archives/list/[email protected]/thread/W7TJUGEIZONXKJD6DWVYASM2KTYWZ6RI/
- https://www.suse.com/security/cve/CVE-2020-8284
- https://www.suse.com/security/cve/CVE-2020-8285
- https://www.suse.com/security/cve/CVE-2020-8286