Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian: DSA-4286-1 Critical: cURL NTLM Authentication Buffer Overflow

debian
Calendar Grey September 5, 2018
Debian Logo
Debian Security Notice DSA-4287-2 tackles a critical issue within OpenSSL affecting session handling. Prompt updates advised.
Zhaoyang Wu discovered that cURL, an URL transfer library, contains a buffer overflow in the NTLM authentication code triggered by passwords that exceed 2GB in length on 32bit syst...

Summary

See https://curl.se/docs/CVE-2018-14618.html for more information.

For the stable distribution (stretch), this problem has been fixed in
version 7.52.1-5+deb9u7.

We recommend that you upgrade your curl packages.

For the detailed security status of curl please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/curl

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: curl
CVE ID: CVE-2018-14618

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here