[CLSA-2022:1663184487] Fix CVE(s): CVE-2022-35252
Type:
security
Severity:
Low
Release date:
2022-09-14 19:41:27 UTC
Description:
* SECURITY UPDATE: When curl sends back to an HTTP(S) server cookies with control bytes, it might make the server return a 400 response - debian/patches/CVE-2022-35252.patch: reject cookies with control bytes 0x01-0x1f (except 0x09) plus 0x7f - CVE-2022-35252
Updated packages:
  • curl_7.47.0-1ubuntu2.23+tuxcare.els5_amd64.deb
    sha:6a8505214b0e0ac9679da0e7570f7217c6d11a4d
  • libcurl3_7.47.0-1ubuntu2.23+tuxcare.els5_amd64.deb
    sha:1875b2cbf45adb799a0eeb5ccab3f6b955bf4420
  • libcurl3-gnutls_7.47.0-1ubuntu2.23+tuxcare.els5_amd64.deb
    sha:5b35c1af719dd7fdf9f0b855f91ef1c023583285
  • libcurl3-nss_7.47.0-1ubuntu2.23+tuxcare.els5_amd64.deb
    sha:6ac2ed84a2a8718bef42be677ae5843422c04689
  • libcurl4-doc_7.47.0-1ubuntu2.23+tuxcare.els5_all.deb
    sha:6b19dbdb15519cd158e5ef3f4b33b1fd0974bcf9
  • libcurl4-gnutls-dev_7.47.0-1ubuntu2.23+tuxcare.els5_amd64.deb
    sha:3dbb3d3709d36c485abd4a8e32c8deecd19e101e
  • libcurl4-nss-dev_7.47.0-1ubuntu2.23+tuxcare.els5_amd64.deb
    sha:861b6488b06623ae46ca413184d089eb58d8190e
  • libcurl4-openssl-dev_7.47.0-1ubuntu2.23+tuxcare.els5_amd64.deb
    sha:cea48e88ea3afa13dfca9b829bc0647feecccd21
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.