Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Oracle Linux 8 ELSA-2021-3583 Moderate: Curl Network Security Update

oracle
Calendar Grey September 21, 2021
Oracle Linux Logo Esm H88
Oracle Linux Security Notice ELSA-2021-3583 delivers a significant patch addressing vulnerabilities in curl for Oracle Linux 8.
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Summary

[7.61.1-18.el8_4.1] - fix bad connection reuse due to flawed path name checks (CVE-2021-22924) - disable metalink support to fix the following vulnerabilities CVE-2021-22923 - metalink download sends credentials CVE-2021-22922 - wrong content via metalink not discarded

SRPMs

https://oss.oracle.com:443/ol8/SRPMS-updates/curl-7.61.1-18.el8_4.1.src.rpm

x86_64

curl-7.61.1-18.el8_4.1.x86_64.rpm libcurl-7.61.1-18.el8_4.1.i686.rpm libcurl-7.61.1-18.el8_4.1.x86_64.rpm libcurl-devel-7.61.1-18.el8_4.1.i686.rpm libcurl-devel-7.61.1-18.el8_4.1.x86_64.rpm libcurl-minimal-7.61.1-18.el8_4.1.i686.rpm libcurl-minimal-7.61.1-18.el8_4.1.x86_64.rpm

aarch64

curl-7.61.1-18.el8_4.1.aarch64.rpm libcurl-7.61.1-18.el8_4.1.aarch64.rpm libcurl-devel-7.61.1-18.el8_4.1.aarch64.rpm libcurl-minimal-7.61.1-18.el8_4.1.aarch64.rpm

Related CVEs: CVE-2021-22922 CVE-2021-22923 CVE-2021-22924

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here