Date: Wed, 31 Mar 2010 16:58:49 -0500 Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Moderate: curl on SL3.x i386/x86_64 Comments: To: "scientific-linux-errata@fnal.gov" Synopsis: Moderate: curl security update Issue date: 2010-03-30 CVE Names: CVE-2010-0734 Wesley Miaw discovered that when deflate compression was used, libcurl could call the registered write callback function with data exceeding the documented limit. A malicious server could use this flaw to crash an application using libcurl or, potentially, execute arbitrary code. Note: This issue only affected applications using libcurl that rely on the documented data size limit, and that copy the data to the insufficiently sized buffer. (CVE-2010-0734) All running applications using libcurl must be restarted for the update to take effect. SL 3.0.x SRPMS: curl-7.10.6-11.rhel3.src.rpm i386: curl-7.10.6-11.rhel3.i386.rpm curl-devel-7.10.6-11.rhel3.i386.rpm x86_64: curl-7.10.6-11.rhel3.i386.rpm curl-7.10.6-11.rhel3.x86_64.rpm curl-devel-7.10.6-11.rhel3.x86_64.rpm -Connie Sieh -Troy Dawson