Security update for curl
This update for curl fixes the following issues: - CVE-2017-1000100: TFP sends more than buffer size and it could lead to a denial of service (bsc#1051644) - CVE-2017-7407: ourWriteOut function problem could lead to a heap buffer over-read (bsc#1032309) - CVE-2016-9586: libcurl printf issue could lead to buffer overflow (bsc#1015332)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for curl fixes the following issues: - CVE-2017-1000100: TFP sends more than buffer size and it could lead to a denial of service (bsc#1051644) - CVE-2017-7407: ourWriteOut function problem could lead to a heap buffer over-read (bsc#1032309) - CVE-2016-9586: libcurl printf issue could lead to buffer overflow (bsc#1015332)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1015332
- https://bugzilla.suse.com/1032309
- https://bugzilla.suse.com/1051644
- https://www.suse.com/security/cve/CVE-2016-9586
- https://www.suse.com/security/cve/CVE-2017-1000100
- https://www.suse.com/security/cve/CVE-2017-7407
- https://www.suse.com/support/update/announcement/2017/suse-su-20172312-1/