Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 12.04 ESM: USN-3441-2 Critical Curl Denial Of Service Issues

ubuntu
Calendar Grey October 23, 2017
Scroller Ubuntu
Update addressing multiple curl security flaws in Ubuntu 12.04 ESM released on October 23, 2017. Explore the vulnerabilities and their corresponding fixes.
Several security issues were fixed in curl.

Summary

Several security issues were fixed in curl.

Software Description:

- curl: HTTP, HTTPS, and FTP client and client libraries

Details:

USN-3441-1 fixed several vulnerabilities in curl. This update

provides the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

 Daniel Stenberg discovered that curl incorrectly handled large

 floating point output. A remote attacker could use this issue to cause

 curl to crash, resulting in a denial of service, or possibly execute

 arbitrary code. (CVE-2016-9586)

 Even Rouault discovered that curl incorrectly handled large file names

 when doing TFTP transfers. A remote attacker could use this issue to

 cause curl to crash, resulting in a denial of service, or possibly

 obtain sensitive memory contents. (CVE-2017-1000100)

 Brian Carpenter and Yongji Ouyang discovered that curl incorrectly

 handled numerical range globbing. A remote attacker could use this

 issue to cause curl to crash, result...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  curl                            7.22.0-3ubuntu4.18
  libcurl3                        7.22.0-3ubuntu4.18
  libcurl3-gnutls                 7.22.0-3ubuntu4.18
  libcurl3-nss                    7.22.0-3ubuntu4.18

In general, a standard system update will make all the necessary
changes.

References

  https://ubuntu.com/security/notices/USN-3441-2

  https://ubuntu.com/security/notices/USN-3441-1

  CVE-2016-9586, CVE-2017-1000100, CVE-2017-1000254, CVE-2017-1000257,

  CVE-2017-7407

Severity
critical
Lowest
Low
Medium
High
Critical

October 23, 2017

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.