Alerts This Week
Warning Icon 1 474
Alerts This Week
Warning Icon 1 474

Mageia: 2020-0282 Moderate: Curl Password Leak and Overwrite Risks

mageia
Calendar Grey July 5, 2020
Dist Mageia Esm H88
The latest iteration of Mageia's curl patch effectively mitigates risks associated with potential password disclosure and remote file overwrite vulnerabilities.
Updated curl packages fix security vulnerabilities: libcurl can be tricked to prepend a part of the password to the host name before it resolves it, potentially leaking the partia...

Summary

Updated curl packages fix security vulnerabilities:
libcurl can be tricked to prepend a part of the password to the host name before it resolves it, potentially leaking the partial password over the network and to the DNS server(s) (CVE-2020-8169).
curl can be tricked by a malicious server to overwrite a local file when using -J (--remote-header-name) and -i (--include) in the same command line (CVE-2020-8177).
The curl package has been updated to version 7.71.0, fixing these issues and other bugs.

References

- https://bugs.mageia.org/show_bug.cgi?id=26858

- https://curl.se/docs/CVE-2020-8169.html

- https://curl.se/docs/CVE-2020-8177.html

- https://curl.se/changes.html

- https://www.cve.org/CVERecord?id=CVE-2020-8169

- https://www.cve.org/CVERecord?id=CVE-2020-8177

Resolution

SRPMS

- 7/core/curl-7.71.0-1.mga7

Publication date: 05 Jul 2020
URL: https://advisories.mageia.org/MGASA-2020-0282.html
Type: security
CVE: CVE-2020-8169, CVE-2020-8177

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here