Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in curl.
Software Description:
- curl: HTTP, HTTPS, and FTP client and client libraries
Details:
It was discovered that curl incorrectly reused client certificates when
built with NSS. A remote attacker could possibly use this issue to hijack
the authentication of a TLS connection. (CVE-2016-7141)
Nguyen Vu Hoang discovered that curl incorrectly handled escaping certain
strings. A remote attacker could possibly use this issue to cause curl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2016-7167)
It was discovered that curl incorrectly handled storing cookies. A remote
attacker could possibly use this issue to inject cookies for arbitrary
domains in the cookie jar. (CVE-2016-8615)
It was discovered that curl incorrect handled case when comparing user
names and passwords. A remote attacker with knowledge of a case-insensitive
version of the correct password could possibly use this i...
The problem can be corrected by updating your system to the following package versions: Ubuntu 16.10: libcurl3 7.50.1-1ubuntu1.1 libcurl3-gnutls 7.50.1-1ubuntu1.1 libcurl3-nss 7.50.1-1ubuntu1.1 Ubuntu 16.04 LTS: libcurl3 7.47.0-1ubuntu2.2 libcurl3-gnutls 7.47.0-1ubuntu2.2 libcurl3-nss 7.47.0-1ubuntu2.2 Ubuntu 14.04 LTS: libcurl3 7.35.0-1ubuntu2.10 libcurl3-gnutls 7.35.0-1ubuntu2.10 libcurl3-nss 7.35.0-1ubuntu2.10 Ubuntu 12.04 LTS: libcurl3 7.22.0-3ubuntu4.17 libcurl3-gnutls 7.22.0-3ubuntu4.17 libcurl3-nss 7.22.0-3ubuntu4.17 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-3123-1
CVE-2016-7141, CVE-2016-7167, CVE-2016-8615, CVE-2016-8616,
CVE-2016-8617, CVE-2016-8618, CVE-2016-8619, CVE-2016-8620,
CVE-2016-8621, CVE-2016-8622, CVE-2016-8623, CVE-2016-8624
Get the latest Linux and open source security news straight to your inbox.