Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

SUSE: 2019:0339-1 Important: Curl Security Update Launched

suse
Calendar Grey February 13, 2019
Dist Suse Esm H88
Red Hat announces critical patch for wget addressing various concerns. Resolves five security flaws for clients.
An update that fixes 6 vulnerabilities is now available

Summary

This update for curl fixes the following issues: Security issues fixed: - CVE-2019-3822: Fixed a NTLMv2 type-3 header stack buffer overflow (bsc#1123377). - CVE-2019-3823: Fixed an out-of-bounds read in the SMTP end-of-response (bsc#1123378). - CVE-2018-16890: Fixed an out-of-bounds buffer read in NTLM type2 (bsc#1123371). - CVE-2018-16842: Fixed an out-of-bounds read in tool_msgs.c (bsc#1113660). - CVE-2018-16840: Fixed a use-after-free in handle close (bsc#1113029). - CVE-2018-16839: Fixed an SASL password overflow caused by an integer overflow (bsc#1112758). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product:

References

#1112758 #1113029 #1113660 #1123371 #1123377

#1123378

Cross- CVE-2018-16839 CVE-2018-16840 CVE-2018-16842

CVE-2018-16890 CVE-2019-3822 CVE-2019-3823

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP4

SUSE Linux Enterprise Server 12-SP4

SUSE Linux Enterprise Desktop 12-SP4

https://www.suse.com/security/cve/CVE-2018-16839.html

https://www.suse.com/security/cve/CVE-2018-16840.html

https://www.suse.com/security/cve/CVE-2018-16842.html

https://www.suse.com/security/cve/CVE-2018-16890.html

https://www.suse.com/security/cve/CVE-2019-3822.html

https://www.suse.com/security/cve/CVE-2019-3823.html

https://bugzilla.suse.com/1112758

https://bugzilla.suse.com/1113029

https://bugzilla.suse.com/1113660

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2019:0339-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here