Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 550
Alerts This Week
Warning Icon 1 550

SUSE: 2018:1323-1 Moderate: curl Buffer Overflow and DoS Issues

suse
Calendar Grey May 17, 2018
Scroller Suse
Critical SUSE Security Patch for wget fixes multiple vulnerabilities that could lead to potential exploitation, including risks of a security breach.
An update that solves three vulnerabilities and has 7 fixes is now available

Summary

This update for curl fixes the following issues: curl was updated to version 7.37.0 (fate#325339 bsc#1084137) This update syncs the curl version to the one in SUSE Linux Enterprise 12 and is full binary compatible to the previous version. This update is done to allow other third party software like "R" to be able to be used on the SUSE Linux Enterprise 11 codebase. Following security issues were fixed: - CVE-2018-1000120: A buffer overflow exists in the FTP URL handling that allowed an attacker to cause a denial of service or possible code execution (bsc#1084521). - CVE-2018-1000121: A NULL pointer dereference exists in the LDAP code that allowed an attacker to cause a denial of service (bsc#1084524). - CVE-2018-1000122: A buffer over-read exists in the RTSP+RTP handling

References

#1081056 #1083463 #1084137 #1084521 #1084524

#1084532 #1085124 #1086825 #1087922 #1090194

Cross- CVE-2018-1000120 CVE-2018-1000121 CVE-2018-1000122

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Server 11-SP3-LTSS

SUSE Linux Enterprise Server 11-SECURITY

SUSE Linux Enterprise Point of Sale 11-SP3

SUSE Linux Enterprise Debuginfo 11-SP4

SUSE Linux Enterprise Debuginfo 11-SP3

https://www.suse.com/security/cve/CVE-2018-1000120.html

https://www.suse.com/security/cve/CVE-2018-1000121.html

https://www.suse.com/security/cve/CVE-2018-1000122.html

https://bugzilla.suse.com/1081056

https://bugzilla.suse.com/1083463

https://bugzilla.suse.com/1084137

Announcement ID: SUSE-SU-2018:1323-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.