[CLSA-2022:1655317708] Fix CVE(s): CVE-2022-22576
Type:
security
Severity:
Important
Release date:
2022-06-15 18:28:28 UTC
Description:
* SECURITY UPDATE: Reusing OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials - debian/patches/CVE-2022-22576.patch: Check additional SASL parameters for connection reuse - CVE-2022-22576
Updated packages:
  • curl_7.47.0-1ubuntu2.23+tuxcare.els1_amd64.deb
    sha:6b20e7fe95e246ce9ffc9179cd7e75d1522e5a2b
  • libcurl3_7.47.0-1ubuntu2.23+tuxcare.els1_amd64.deb
    sha:9b6a1acf184ba2f86baae71c14a9779e015e9c95
  • libcurl3-gnutls_7.47.0-1ubuntu2.23+tuxcare.els1_amd64.deb
    sha:184303e73db966fb39276f4b922d2290df4d3820
  • libcurl3-nss_7.47.0-1ubuntu2.23+tuxcare.els1_amd64.deb
    sha:680899edaf3bb68efd74f46a88f1e9b818566e6d
  • libcurl4-doc_7.47.0-1ubuntu2.23+tuxcare.els1_all.deb
    sha:ef2468601385dd84302731ab9107fd060a9cac98
  • libcurl4-gnutls-dev_7.47.0-1ubuntu2.23+tuxcare.els1_amd64.deb
    sha:0e1d3c04053b8ee5d5160a3e436fde7268608b95
  • libcurl4-nss-dev_7.47.0-1ubuntu2.23+tuxcare.els1_amd64.deb
    sha:621e1a76ef739aa3bd66e09942dce4723ff1cc29
  • libcurl4-openssl-dev_7.47.0-1ubuntu2.23+tuxcare.els1_amd64.deb
    sha:5b956950641797d610bccf190e6709722c98fd33
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.