Security update for curl
This curl update fixes the following security issues: * bnc#868627: wrong re-use of connections (CVE-2014-0138). * bnc#868629: IP address wildcard certificate validation (CVE-2014-0139). * bnc#870444: --insecure option inappropriately enforcing security safeguard. Security Issue references: * CVE-2014-0138 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0138> * CVE-2014-0139 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0139>
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This curl update fixes the following security issues: * bnc#868627: wrong re-use of connections (CVE-2014-0138). * bnc#868629: IP address wildcard certificate validation (CVE-2014-0139). * bnc#870444: --insecure option inappropriately enforcing security safeguard. Security Issue references: * CVE-2014-0138 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0138> * CVE-2014-0139 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0139>
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/824517
- https://bugzilla.suse.com/849596
- https://bugzilla.suse.com/858673
- https://bugzilla.suse.com/868627
- https://bugzilla.suse.com/868629
- https://bugzilla.suse.com/870444
- https://bugzilla.suse.com/927174
- https://bugzilla.suse.com/927556
- https://bugzilla.suse.com/927746
- https://bugzilla.suse.com/928533
- https://www.suse.com/security/cve/CVE-2013-2174
- https://www.suse.com/security/cve/CVE-2013-4545
- https://www.suse.com/security/cve/CVE-2014-0015
- https://www.suse.com/security/cve/CVE-2014-0138
- https://www.suse.com/security/cve/CVE-2014-0139
- https://www.suse.com/security/cve/CVE-2015-3143
- https://www.suse.com/security/cve/CVE-2015-3148
- https://www.suse.com/security/cve/CVE-2015-3153
- https://www.suse.com/support/update/announcement/2015/suse-su-20150962-1/