Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
This update for curl fixes the following issues: curl was updated to version 7.37.0 (fate#325339 bsc#1084137) This update syncs the curl version to the one in SUSE Linux Enterprise 12 and is full binary compatible to the previous version. This update is done to allow other third party software like "R" to be able to be used on the SUSE Linux Enterprise 11 codebase. Following security issues were fixed: - CVE-2018-1000120: A buffer overflow exists in the FTP URL handling that allowed an attacker to cause a denial of service or possible code execution (bsc#1084521). - CVE-2018-1000121: A NULL pointer dereference exists in the LDAP code that allowed an attacker to cause a denial of service (bsc#1084524). - CVE-2018-1000122: A buffer over-read exists in the RTSP+RTP handling
#1081056 #1083463 #1084137 #1084521 #1084524
#1084532 #1085124 #1086825 #1087922 #1090194
Cross- CVE-2018-1000120 CVE-2018-1000121 CVE-2018-1000122
Affected Products:
SUSE Linux Enterprise Software Development Kit 11-SP4
SUSE Linux Enterprise Server 11-SP4
SUSE Linux Enterprise Server 11-SP3-LTSS
SUSE Linux Enterprise Server 11-SECURITY
SUSE Linux Enterprise Point of Sale 11-SP3
SUSE Linux Enterprise Debuginfo 11-SP4
SUSE Linux Enterprise Debuginfo 11-SP3
https://www.suse.com/security/cve/CVE-2018-1000120.html
https://www.suse.com/security/cve/CVE-2018-1000121.html
https://www.suse.com/security/cve/CVE-2018-1000122.html
https://bugzilla.suse.com/1081056
https://bugzilla.suse.com/1083463
https://bugzilla.suse.com/1084137
Get the latest Linux and open source security news straight to your inbox.