RHSA-2015:1254Medium
Red Hat Security Advisory: curl security, bug fix, and enhancement update
🔗 CVE IDs covered (5)
📋 Description
CVE-2014-3613 — curl: incorrect handling of IP addresses in cookie domain CVE-2014-3707 — curl: incorrect handle duplication after COPYPOSTFIELDS CVE-2014-8150 — curl: URL request injection vulnerability in parseurlandfillconn() CVE-2015-3143 — curl: re-using authenticated connection when unauthenticated CVE-2015-3148 — curl: Negotiate not treated as connection-oriented
🔗 References (21)
- selfhttps://access.redhat.com/errata/RHSA-2015:1254
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=835898
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=883002
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=997185
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1008178
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1011083
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1011101
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1058767
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1104160
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1136154
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1154059
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1154747
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1154941
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1156422
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1161163
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1168137
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1178692
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1213306
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1213351
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2015/rhsa-2015_1254.json