FlawAtlas
Search the atlas
SUSE-SU-2018:0214-1 Not scored

Security update for curl

This update for curl fixes several issues. These security issues were fixed: - CVE-2017-1000254: Fix FTP PWD response parser out of bounds read (bsc#1061876). - CVE-2018-1000007: Prevent leaking authentication data to third parties when following redirects (bsc#1077001) Also the following adjustment was made: - Set DEFAULT_SUSE as the default cipher list (bsc#1027712)

Exploit probability Not scored
Published January 25, 2018
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Studio Onsite 1.3 curl

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2018:0214-1

This update for curl fixes several issues. These security issues were fixed: - CVE-2017-1000254: Fix FTP PWD response parser out of bounds read (bsc#1061876). - CVE-2018-1000007: Prevent leaking authentication data to third parties when following redirects (bsc#1077001) Also the following adjustment was made: - Set DEFAULT_SUSE as the default cipher list (bsc#1027712)

View original source

05 / REFERENCES

Further evidence