USN-2399-1: curl vulnerability
10 November 2014
curl could expose sensitive information over the network.
Releases
Packages
- curl - HTTP, HTTPS, and FTP client and client libraries
Details
Symeon Paraschoudis discovered that curl incorrectly handled memory when
being used with CURLOPT_COPYPOSTFIELDS and curl_easy_duphandle(). This may
result in sensitive data being incorrectly sent to the remote server.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 14.10
Ubuntu 14.04
Ubuntu 12.04
-
libcurl3
-
7.22.0-3ubuntu4.11
-
libcurl3-gnutls
-
7.22.0-3ubuntu4.11
-
libcurl3-nss
-
7.22.0-3ubuntu4.11
Ubuntu 10.04
In general, a standard system update will make all the necessary changes.