Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Mageia 9 MGASA-2024-0099 moderate: curl HTTP/2 memory leak issue

mageia
Calendar Grey March 29, 2024
Dist Mageia Esm H88
Recent curl updates tackle various security vulnerabilities, including memory overflow risks and the use of outdated protocols. Find out more information.
CVE-2024-2004: Usage of disabled protocol If all protocols are disabled at run-time with none being added, curl/libcurl would still allow communication with the default set of allo...

Summary

CVE-2024-2004: Usage of disabled protocol If all protocols are disabled at run-time with none being added, curl/libcurl would still allow communication with the default set of allowed protocols, including some that are unencrypted. CVE-2024-2398: HTTP/2 push headers memory-leak A memory leak could occur when an application enabled HTTP/2 server push and the server sent a large number of headers.

References

- https://bugs.mageia.org/show_bug.cgi?id=33020

- https://curl.se/docs/CVE-2024-2004.html

- https://curl.se/docs/CVE-2024-2398.html

- https://www.cve.org/CVERecord?id=CVE-2024-2004

- https://www.cve.org/CVERecord?id=CVE-2024-2379

- https://www.cve.org/CVERecord?id=CVE-2024-2398

- https://www.cve.org/CVERecord?id=CVE-2024-2466

Resolution

SRPMS

- 9/core/curl-7.88.1-4.3.mga9

Publication date: 29 Mar 2024
URL: https://advisories.mageia.org/MGASA-2024-0099.html
Type: security
CVE: CVE-2024-2004, CVE-2024-2379, CVE-2024-2398, CVE-2024-2466

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here