Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 12.10 USN-1721-1 Moderate: Curl Malicious URL Threat

ubuntu
Calendar Grey February 12, 2013
Scroller Ubuntu
Ensure your Ubuntu system is patched for the curl security flaw detected on February 12, 2013, by performing a system update.
curl could be made to crash or run programs if it opened a malicious URL.

Summary

curl could be made to crash or run programs if it opened a malicious URL.

Software Description:

- curl: HTTP, HTTPS, and FTP client and client libraries

Details:

It was discovered that curl incorrectly handled SASL authentication when

communicating over POP3, SMTP or IMAP. If a user or automated system were

tricked into processing a specially crafted URL, an attacker could cause

a denial of service, or possibly execute arbitrary code. The default

compiler options for affected releases should reduce the vulnerability to a

denial of service.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
  libcurl3                        7.27.0-1ubuntu1.1
  libcurl3-gnutls                 7.27.0-1ubuntu1.1
  libcurl3-nss                    7.27.0-1ubuntu1.1

In general, a standard system update will make all the necessary changes.

References

CVE-2013-0249

February 12, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.