[CLSA-2024:1726313254] Fix CVE(s): CVE-2024-7264
Type:
security
Severity:
Moderate
Release date:
2024-09-14 11:27:37 UTC
Description:
* SECURITY UPDATE: Heap Buffer Overflow in ASN.1 Parser - debian/patches/CVE-2024-7264.patch: Clean up GTime2str function to handle optional fractional seconds properly. Fix GTime2str() issues and add unit tests to verify correct behaviour - CVE-2024-7264
Updated packages:
  • curl_7.47.0-1ubuntu2.23+tuxcare.els13_amd64.deb
    sha:afeade26a120e12cb8781efef0cd15eee8853dbf
  • libcurl3_7.47.0-1ubuntu2.23+tuxcare.els13_amd64.deb
    sha:8a6e3fab03bc861ab4c3681827dedb11dd5e736f
  • libcurl3-gnutls_7.47.0-1ubuntu2.23+tuxcare.els13_amd64.deb
    sha:e7bfcfa8875e6397972c7cfdce64c61dc380fa30
  • libcurl3-nss_7.47.0-1ubuntu2.23+tuxcare.els13_amd64.deb
    sha:98b7cf219c806eb7dd4b6e5f5c3270d02e3a4b5e
  • libcurl4-doc_7.47.0-1ubuntu2.23+tuxcare.els13_all.deb
    sha:74a565b5c6a18c970933332165938ece405911de
  • libcurl4-gnutls-dev_7.47.0-1ubuntu2.23+tuxcare.els13_amd64.deb
    sha:8378f842328c9bc4290849051d3069b3d801cf20
  • libcurl4-nss-dev_7.47.0-1ubuntu2.23+tuxcare.els13_amd64.deb
    sha:a474af27e4ed90621d1e35d7d9f3e1398a9385fd
  • libcurl4-openssl-dev_7.47.0-1ubuntu2.23+tuxcare.els13_amd64.deb
    sha:4802f7150a1c6e21832e4180802c9c1470631688
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.