[CLSA-2023:1697816385] curl: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2023-10-20
Description:
- CVE-2022-27782: check additional TLS or SSH connection parameters that should have prohibited connection reuse - CVE-2023-27534: fix SFTP path '~' resolving discrepancy - fix read off end of array for SCP home directory case
Updated packages:
  • curl-7.29.0-59.el7_9.1.tuxcare.els2.x86_64.rpm
    sha:c6b8cd1d033f66ec092dd6ec364d6e1bb22b513e
  • libcurl-7.29.0-59.el7_9.1.tuxcare.els2.i686.rpm
    sha:d779dd419635c2558f2f45cbac233ca2659ff107
  • libcurl-7.29.0-59.el7_9.1.tuxcare.els2.x86_64.rpm
    sha:7e7587538c86987f9c8a0b96915525a5e013ab09
  • libcurl-devel-7.29.0-59.el7_9.1.tuxcare.els2.i686.rpm
    sha:a696267b1ffa00bc5dfa92272e487a1bdf77e189
  • libcurl-devel-7.29.0-59.el7_9.1.tuxcare.els2.x86_64.rpm
    sha:d8fe927577f34acaf86d37f68430ef4dcc3e21d3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.