Send ubuntu-security-announce mailing list submissions to
ubuntu-security-announce@lists.ubuntu.com
To subscribe or unsubscribe via the World Wide Web, visit
https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
or, via email, send a message with subject or body 'help' to
ubuntu-security-announce-request@lists.ubuntu.com
You can reach the person managing the list at
ubuntu-security-announce-owner@lists.ubuntu.com
When replying, please edit your Subject line so it is more specific
than "Re: Contents of ubuntu-security-announce digest..."
Today's Topics:
1. [USN-2346-1] curl vulnerabilities (Marc Deslauriers)
----------------------------------------------------------------------
Message: 1
Date: Mon, 15 Sep 2014 08:28:05 -0400
From: Marc Deslauriers <marc.deslauriers@canonical.com>
To: ubuntu-security-announce@lists.ubuntu.com
Subject: [USN-2346-1] curl vulnerabilities
Message-ID: <5416DB55.2060802@canonical.com>
Content-Type: text/plain; charset="utf-8"
==========================================================================
Ubuntu Security Notice USN-2346-1
September 15, 2014
curl vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS
Summary:
Several security issues were fixed in curl.
Software Description:
- curl: HTTP, HTTPS, and FTP client and client libraries
Details:
Tim Ruehsen discovered that curl incorrectly handled partial literal IP
addresses. This could lead to the disclosure of cookies to the wrong site,
and malicious sites being able to set cookies for others. (CVE-2014-3613)
Tim Ruehsen discovered that curl incorrectly allowed cookies to be set
for Top Level Domains (TLDs). This could allow a malicious site to set a
cookie that gets sent to other sites. (CVE-2014-3620)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
libcurl3 7.35.0-1ubuntu2.1
libcurl3-gnutls 7.35.0-1ubuntu2.1
libcurl3-nss 7.35.0-1ubuntu2.1
Ubuntu 12.04 LTS:
libcurl3 7.22.0-3ubuntu4.10
libcurl3-gnutls 7.22.0-3ubuntu4.10
libcurl3-nss 7.22.0-3ubuntu4.10
Ubuntu 10.04 LTS:
libcurl3 7.19.7-1ubuntu1.9
libcurl3-gnutls 7.19.7-1ubuntu1.9
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2346-1
CVE-2014-3613, CVE-2014-3620
Package Information:
https://launchpad.net/ubuntu/+source/curl/7.35.0-1ubuntu2.1
https://launchpad.net/ubuntu/+source/curl/7.22.0-3ubuntu4.10
https://launchpad.net/ubuntu/+source/curl/7.19.7-1ubuntu1.9
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: OpenPGP digital signature
URL: <https://lists.ubuntu.com/archives/ubuntu-security-announce/attachments/20140915/3be35a8d/attachment-0001.pgp>
------------------------------
--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
End of ubuntu-security-announce Digest, Vol 120, Issue 10
*********************************************************
News
Subscribe to:
Post Comments (Atom)
Blog Archive
-
▼
2014
(407)
-
▼
September
(48)
- Through Microservices, a Renewed Push for Simplici...
- Intel, Cisco, HP, Others Form NFV Consortium
- Arduino to Sell 3D Printer—$800 in Kit Form or $1,...
- Piston’s McKenty to Leave Company He Founded for P...
- Chromecast Getting Competition from Firefox OS-Pow...
- Facebook has Over 200 Open Source Projects on GitHub
- Distribution Release: CentOS 5.11
- Apache Storm is Ready for Prime Time
- Scribbleton Has a Ton of Potential
- eBay, PayPal Breakup an OpenStack Private Cloud Sp...
- VMware's Role in OpenStack: A Second Look
- Bringing Together a Disconnected Team
- Fedora Might Try A New Scheduling Strategy For Its...
- Ten Fastest-Growing IT Skills Offer Opportunities
- Open Sourcing Automation Tools for Testing Linux I...
- NVIDIA GeForce GTX 980: The Best GPU For Linux Gamers
- Open Source Drives Innovation in Another Multi-Bil...
- ubuntu-security-announce Digest, Vol 120, Issue 19
- Protect yourself from the big bad shellshock
- Web Software vs. Native Linux Software
- Tor Executive Director Hints at Firefox Integration
- HP Unveils ARM-Based Moonshot Servers
- Eclipse Foundation Delivers Open IoT Stack for Java
- The Internet Is Broken, and Shellshock Is Just the...
- Improved Patch Tackles New Shellshock Bash Bug Att...
- Cloudflare Just Added SSL Encryption to Two Millio...
- Shellshock Makes Heartbleed Look Insignificant
- Open, Open, Open: OpenDaylight Helium is Here
- LibreSSL: More Than 30 Days Later
- ubuntu-security-announce Digest, Vol 120, Issue 18
- ubuntu-security-announce Digest, Vol 120, Issue 17
- ubuntu-security-announce Digest, Vol 120, Issue 16
- Microsoft VP Scott Charney Architect of Trustworth...
- ubuntu-security-announce Digest, Vol 120, Issue 15
- ubuntu-security-announce Digest, Vol 120, Issue 14
- ubuntu-security-announce Digest, Vol 120, Issue 13
- ubuntu-security-announce Digest, Vol 120, Issue 12
- ubuntu-security-announce Digest, Vol 120, Issue 11
- ubuntu-security-announce Digest, Vol 120, Issue 10
- ubuntu-security-announce Digest, Vol 120, Issue 9
- ubuntu-security-announce Digest, Vol 120, Issue 8
- ubuntu-security-announce Digest, Vol 120, Issue 7
- ubuntu-security-announce Digest, Vol 120, Issue 6
- ubuntu-security-announce Digest, Vol 120, Issue 5
- ubuntu-security-announce Digest, Vol 120, Issue 4
- ubuntu-security-announce Digest, Vol 120, Issue 3
- ubuntu-security-announce Digest, Vol 120, Issue 2
- ubuntu-security-announce Digest, Vol 120, Issue 1
-
▼
September
(48)
No comments:
Post a Comment