Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 11.10: 1346-1 Moderate: Curl Data Injection Risk

ubuntu
Calendar Grey January 24, 2012
Scroller Ubuntu
Recent security flaw in Ubuntu's curl could permit unauthorized data injection via compromised URLs. Immediate update suggested to ensure protection.
curl could be tricked into injecting arbitrary data if it handled a malicious URL.

Summary

curl could be tricked into injecting arbitrary data if it handled a

malicious URL.

Software Description:

- curl: HTTP, HTTPS, and FTP client and client libraries

Details:

Dan Fandrich discovered that curl incorrectly handled URLs containing

embedded or percent-encoded control characters. If a user or automated

system were tricked into processing a specially crafted URL, arbitrary

data could be injected.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.10:
  libcurl3                        7.21.6-3ubuntu3.2
  libcurl3-gnutls                 7.21.6-3ubuntu3.2
  libcurl3-nss                    7.21.6-3ubuntu3.2

Ubuntu 11.04:
  libcurl3                        7.21.3-1ubuntu1.5
  libcurl3-gnutls                 7.21.3-1ubuntu1.5
  libcurl3-nss                    7.21.3-1ubuntu1.5

Ubuntu 10.10:
  libcurl3                        7.21.0-1ubuntu1.3
  libcurl3-gnutls                 7.21.0-1ubuntu1.3

In general, a standard system update will make all the necessary changes.

References

CVE-2012-0036

Severity
important
Lowest
Low
Medium
High
Critical

January 24, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.