Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Slackware 14.2: 2021-146-01 Critical: Curl TLS and Telnet Flaws

slackware
Calendar Grey May 26, 2021
Dist Slackware Esm H88
Protect your Debian installation by applying the most recent wget patches that address urgent vulnerabilities impacting various versions.
New curl packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues

Summary

Here are the details from the Slackware 14.2 ChangeLog: patches/packages/curl-7.77.0-i586-1_slack14.2.txz: Upgraded. This update fixes security issues: schannel cipher selection surprise TELNET stack contents disclosure TLS session caching disaster For more information, see: https://www.cve.org/CVERecord?id=CVE-2021-22297 https://www.cve.org/CVERecord?id=CVE-2021-22298 https://www.cve.org/CVERecord?id=CVE-2021-22901 (* Security fix *)

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 14.0:
Updated package for Slackware x86_64 14.0:
Updated package for Slackware 14.1:
Updated package for Slackware x86_64 14.1:
Updated package for Slackware 14.2:
Updated package for Slackware x86_64 14.2:
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:

MD5 Signatures

Slackware 14.0 package: adc116e85d43d8da97c22afde220a52a curl-7.77.0-i486-1_slack14.0.txz
Slackware x86_64 14.0 package: 7dbc032faa6bdf4135372e020ba73939 curl-7.77.0-x86_64-1_slack14.0.txz
Slackware 14.1 package: 9ee3ccab004ec5ccc6f6616d2a2ebc7a curl-7.77.0-i486-1_slack14.1.txz
Slackware x86_64 14.1 package: 2a644d117a6642b814e60cc5213a273c curl-7.77.0-x86_64-1_slack14.1.txz
Slackware 14.2 package: 992a07e1fc6c0955003ae857464aca33 curl-7.77.0-i586-1_slack14.2.txz
Slackware x86_64 14.2 package: ba613de8f3120ccef88b2c18ae8a8b54 curl-7.77.0-x86_64-1_slack14.2.txz
Slackware -current package: ca4bef5661dd7b54888a505e12a49843 n/curl-7.77.0-i586-1.txz
Slackware x86_64 -current package: bc7cdc8f0b1e9f061771fb2f0d343ed6 n/curl-7.77.0-x86_64-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg curl-7.77.0-i586-1_slack14.2.txz

Related News

Your message here