[CLSA-2022:1661173301] Fix CVE(s): CVE-2022-32208
Type:
security
Severity:
Moderate
Release date:
2022-08-22 13:01:41 UTC
Description:
* SECURITY UPDATE: When curl less than 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. - debian/patches/CVE-2022-32208.patch: krb5: return error properly on decode errors - CVE-2022-32208
Updated packages:
  • curl_7.47.0-1ubuntu2.23+tuxcare.els4_amd64.deb
    sha:7103491c09de2f6d86e98330d3f3834213a238ed
  • libcurl3_7.47.0-1ubuntu2.23+tuxcare.els4_amd64.deb
    sha:e002be08a2d0eaa86ea4e7ab5cd4bb77bee51086
  • libcurl3-gnutls_7.47.0-1ubuntu2.23+tuxcare.els4_amd64.deb
    sha:bb06512efd3f9bfc8be0f29be63f0c90a86c8dae
  • libcurl3-nss_7.47.0-1ubuntu2.23+tuxcare.els4_amd64.deb
    sha:522ff9a9c44095e4b7e8b4cf9a76f69057d51eed
  • libcurl4-doc_7.47.0-1ubuntu2.23+tuxcare.els4_all.deb
    sha:e0eb38e33d834f230fe165d50385015f1374bd24
  • libcurl4-gnutls-dev_7.47.0-1ubuntu2.23+tuxcare.els4_amd64.deb
    sha:697c85b1e2d46db30e346f3b29b6ad78f73cd831
  • libcurl4-nss-dev_7.47.0-1ubuntu2.23+tuxcare.els4_amd64.deb
    sha:4abfc42bb7843ea220aa732a4a27e9af0f3111f1
  • libcurl4-openssl-dev_7.47.0-1ubuntu2.23+tuxcare.els4_amd64.deb
    sha:03c2f215d39635d95c424584009b98872f98a71a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.