• curl vulnerabilities

    From bugz_ubuntu@21:4/110 to Ubuntu Users on Wednesday, June 24, 2020 12:10:02
    curl vulnerabilities

    A security issue affects these releases of Ubuntu and its
    derivatives:

    * Ubuntu 20.04 LTS
    * Ubuntu 19.10
    * Ubuntu 18.04 LTS
    * Ubuntu 16.04 LTS
    * Ubuntu 14.04 ESM
    * Ubuntu 12.04 ESM

    Summary

    Several security issues were fixed in curl.

    Software Description

    * curl - HTTP, HTTPS, and FTP client and client libraries

    Details

    Marek Szlagor, Gregory Jefferis and Jeroen Ooms discovered that
    curl incorrectly handled certain credentials. An attacker could
    possibly use this issue to expose sensitive information. This
    issue only affected Ubuntu 19.10 and Ubuntu 20.04 LTS.
    (CVE-2020-8169)

    It was discovered that curl incorrectly handled certain
    parameters. An attacker could possibly use this issue to overwrite
    a local file. (CVE-2020-8177)

    Update instructions

    The problem can be corrected by updating your system to the
    following package versions:

    Ubuntu 20.04 LTS
    curl - 7.68.0-1ubuntu2.1
    libcurl3-gnutls - 7.68.0-1ubuntu2.1
    libcurl3-nss - 7.68.0-1ubuntu2.1
    libcurl4 - 7.68.0-1ubuntu2.1

    Ubuntu 19.10
    curl - 7.65.3-1ubuntu3.1
    libcurl3-gnutls - 7.65.3-1ubuntu3.1
    libcurl3-nss - 7.65.3-1ubuntu3.1
    libcurl4 - 7.65.3-1ubuntu3.1

    Ubuntu 18.04 LTS
    curl - 7.58.0-2ubuntu3.9
    libcurl3-gnutls - 7.58.0-2ubuntu3.9
    libcurl3-nss - 7.58.0-2ubuntu3.9
    libcurl4 - 7.58.0-2ubuntu3.9

    Ubuntu 16.04 LTS
    curl - 7.47.0-1ubuntu2.15
    libcurl3 - 7.47.0-1ubuntu2.15
    libcurl3-gnutls - 7.47.0-1ubuntu2.15
    libcurl3-nss - 7.47.0-1ubuntu2.15

    Ubuntu 14.04 ESM
    curl - 7.35.0-1ubuntu2.20+esm4
    libcurl3 - 7.35.0-1ubuntu2.20+esm4
    libcurl3-gnutls - 7.35.0-1ubuntu2.20+esm4
    libcurl3-nss - 7.35.0-1ubuntu2.20+esm4

    Ubuntu 12.04 ESM
    curl - 7.22.0-3ubuntu4.28
    libcurl3 - 7.22.0-3ubuntu4.28
    libcurl3-gnutls - 7.22.0-3ubuntu4.28
    libcurl3-nss - 7.22.0-3ubuntu4.28

    To update your system, please follow these instructions:
    https://wiki.ubuntu.com/Security/Upgrades.

    In general, a standard system update will make all the necessary
    changes.

    References

    * CVE-2020-8169
    * CVE-2020-8177

    --- Mystic BBS v1.12 A45 (Linux/64)
    * Origin: BZ&BZ BBS (21:4/110)