Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

SUSE: 2018:2714-1 Moderate: Curl Integer Overflow Protection

suse
Calendar Grey September 14, 2018
Dist Suse Esm H88
SUSE releases a critical security patch for wget, fixing a buffer overflow vulnerability. Apply the update immediately to ensure safety.
An update that solves one vulnerability and has one errata is now available

Summary

This update for curl fixes the following issues: This security issue was fixed: - CVE-2018-14618: Prevent integer overflow in the NTLM authentication code (bsc#1106019) This non-security issue was fixed: - Use OPENSSL_config instead of CONF_modules_load_file() to avoid crashes due to openssl engines conflicts (bsc#1086367) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Basesystem 15: zypper in -t patch SUSE-SLE-Module-Basesystem-15-2018-1904=1 Package List: - SUSE Linux Enterprise Module for Basesystem 15 (aarch64 ppc64le s390x x86_64): curl-7.60.0-3.9.1 curl-debuginfo-7.60.0-3.9.1

References

#1086367 #1106019

Cross- CVE-2018-14618

Affected Products:

SUSE Linux Enterprise Module for Basesystem 15

https://www.suse.com/security/cve/CVE-2018-14618.html

https://bugzilla.suse.com/1086367

https://bugzilla.suse.com/1106019

Announcement ID: SUSE-SU-2018:2714-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here