Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

SUSE Studio Onsite 1.3: SUSE-SU-2016:2700-1 Important: curl Issues

suse
Calendar Grey November 2, 2016
Scroller Suse
SUSE Security Update for wget tackles severe vulnerabilities in SUSE Studio Onsite, providing various solutions to enhance protection.
An update that fixes 13 vulnerabilities is now available

Summary

This update for curl fixes the following issues: - CVE-2016-8624: invalid URL parsing with '#' (bsc#1005646) - CVE-2016-8623: Use-after-free via shared cookies (bsc#1005645) - CVE-2016-8621: curl_getdate read out of bounds (bsc#1005642) - CVE-2016-8619: double-free in krb5 code (bsc#1005638) - CVE-2016-8618: double-free in curl_maprintf (bsc#1005637) - CVE-2016-8617: OOB write via unchecked multiplication (bsc#1005635) - CVE-2016-8616: case insensitive password comparison (bsc#1005634) - CVE-2016-8615: cookie injection for other servers (bsc#1005633) - CVE-2016-7167: escape and unescape integer overflows (bsc#998760) - CVE-2016-7141: Fixed incorrect reuse of client certificates with NSS not fixed in CVE-2016-5420 (bsc#997420) Patch Instructions:

References

#1005633 #1005634 #1005635 #1005637 #1005638

#1005642 #1005645 #1005646 #997420 #998760

Cross- CVE-2016-5420 CVE-2016-7141 CVE-2016-7167

CVE-2016-8615 CVE-2016-8616 CVE-2016-8617

CVE-2016-8618 CVE-2016-8619 CVE-2016-8620

CVE-2016-8621 CVE-2016-8622 CVE-2016-8623

CVE-2016-8624

Affected Products:

SUSE Studio Onsite 1.3

https://www.suse.com/security/cve/CVE-2016-5420.html

https://www.suse.com/security/cve/CVE-2016-7141.html

https://www.suse.com/security/cve/CVE-2016-7167.html

https://www.suse.com/security/cve/CVE-2016-8615.html

https://www.suse.com/security/cve/CVE-2016-8616.html

https://www.suse.com/security/cve/CVE-2016-8617.html

https://www.suse.com/security/cve/CVE-2016-8618.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2016:2700-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.