Date: Thu, 13 Aug 2009 16:46:56 -0500 Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Moderate: curl on SL5.x i386/x86_64 Comments: To: "scientific-linux-errata@fnal.gov" Synopsis: Moderate: curl security update Issue date: 2009-08-13 CVE Names: CVE-2009-2417 CVE-2009-2417 curl: incorrect verification of SSL certificate with NUL in name Scott Cantor reported that cURL is affected by the previously published "null prefix attack", caused by incorrect handling of NULL characters in X.509 certificates. If an attacker is able to get a carefully-crafted certificate signed by a trusted Certificate Authority, the attacker could use the certificate during a man-in-the-middle attack and potentially confuse cURL into accepting it by mistake. (CVE-2009-2417) All running applications using libcurl must be restarted for the update to take effect. SL 5.x SRPMS: curl-7.15.5-2.1.el5_3.5.src.rpm i386: curl-7.15.5-2.1.el5_3.5.i386.rpm curl-devel-7.15.5-2.1.el5_3.5.i386.rpm x86_64: curl-7.15.5-2.1.el5_3.5.i386.rpm curl-7.15.5-2.1.el5_3.5.x86_64.rpm curl-devel-7.15.5-2.1.el5_3.5.i386.rpm curl-devel-7.15.5-2.1.el5_3.5.x86_64.rpm -Connie Sieh -Troy Dawson