Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

SUSE: 2020:2444-1 Moderate: curl Connection Handling Issue

suse
Calendar Grey September 2, 2020
Dist Suse Esm H88
SUSE Security Update for wget tackles moderate vulnerabilities linked to data transfer protocols. Apply the update promptly to enhance your system's defenses.
An update that fixes one vulnerability is now available

Summary

This update for curl fixes the following issues: - An application that performs multiple requests with libcurl's multi API and sets the 'CURLOPT_CONNECT_ONLY' option, might in rare circumstances experience that when subsequently using the setup connect-only transfer, libcurl will pick and use the wrong connection and instead pick another one the application has created since then. [bsc#1175109, CVE-2020-8231] Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2020-2444=1 - SUSE Linux Enterprise Server 12-SP5:

References

#1175109

Cross- CVE-2020-8231

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP5

SUSE Linux Enterprise Server 12-SP5

https://www.suse.com/security/cve/CVE-2020-8231.html

https://bugzilla.suse.com/1175109

Announcement ID: SUSE-SU-2020:2444-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here