Security update for curl
This update for curl fixes the following issues: Security issues fixed: - CVE-2024-7264: ASN.1 date parser overread (bsc#1228535) - CVE-2024-6197: Freeing stack buffer in utf8asn1str (bsc#1227888) - CVE-2024-2379: QUIC certificate check bypass with wolfSSL (bsc#1221666) - CVE-2024-2466: TLS certificate check bypass with mbedTLS (bsc#1221668) - CVE-2024-2004: Usage of disabled protocol (bsc#1221665) - CVE-2024-2398: HTTP/2 push headers memory-leak (bsc#1221667) Non-security issue fixed: - Fixed various TLS related issues including FTP over SSL transmission timeouts.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for curl fixes the following issues: Security issues fixed: - CVE-2024-7264: ASN.1 date parser overread (bsc#1228535) - CVE-2024-6197: Freeing stack buffer in utf8asn1str (bsc#1227888) - CVE-2024-2379: QUIC certificate check bypass with wolfSSL (bsc#1221666) - CVE-2024-2466: TLS certificate check bypass with mbedTLS (bsc#1221668) - CVE-2024-2004: Usage of disabled protocol (bsc#1221665) - CVE-2024-2398: HTTP/2 push headers memory-leak (bsc#1221667) Non-security issue fixed: - Fixed various TLS related issues including FTP over SSL transmission timeouts.
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1221665
- https://bugzilla.suse.com/1221666
- https://bugzilla.suse.com/1221667
- https://bugzilla.suse.com/1221668
- https://bugzilla.suse.com/1227888
- https://bugzilla.suse.com/1228535
- https://www.suse.com/security/cve/CVE-2024-2004
- https://www.suse.com/security/cve/CVE-2024-2379
- https://www.suse.com/security/cve/CVE-2024-2398
- https://www.suse.com/security/cve/CVE-2024-2466
- https://www.suse.com/security/cve/CVE-2024-6197
- https://www.suse.com/security/cve/CVE-2024-7264
- https://www.suse.com/support/update/announcement/2025/suse-su-202520029-1/