MGASA-2021-0384 - Updated curl packages fix security vulnerabilities Publication date: 27 Jul 2021 URL: https://advisories.mageia.org/MGASA-2021-0384.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-22922, CVE-2021-22923, CVE-2021-22924, CVE-2021-22925 Wrong content via metalink not discarded (CVE-2021-22922). Metalink download sends credentials (CVE-2021-22923). Bad connection reuse due to flawed path name checks (CVE-2021-22924). TELNET stack contents disclosure again (CVE-2021-22925). References: - https://bugs.mageia.org/show_bug.cgi?id=29278 - https://curl.se/docs/CVE-2021-22922.html - https://curl.se/docs/CVE-2021-22923.html - https://curl.se/docs/CVE-2021-22924.html - https://curl.se/docs/CVE-2021-22925.html - https://lists.suse.com/pipermail/sle-security-updates/2021-July/009187.html - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22922 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22923 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22924 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-22925 SRPMS: - 8/core/curl-7.74.0-1.3.mga8