[CLSA-2023:1688070599] Fix CVE(s): CVE-2023-28322, CVE-2023-28321
Type:
security
Severity:
Moderate
Release date:
2023-06-29 20:30:06 UTC
Description:
* SECURITY UPDATE: More POST-after-PUT confusion - debian/patches/CVE-2023-28322.patch: fix mess in upload/method handling - CVE-2023-28322 * SECURITY UPDATE: incorrect IDN wildcard match - debian/patches/CVE-2023-28321.patch: fix erroneous logic in wildcard handling, drop support for wildcards in the middle of domain name - CVE-2023-28321
Updated packages:
  • curl_7.58.0-2ubuntu3.24+tuxcare.els1_amd64.deb
    sha:53abb078965df7bb5ac337d5f723bb86ae698d2c
  • libcurl3-gnutls_7.58.0-2ubuntu3.24+tuxcare.els1_amd64.deb
    sha:69db79e98f96269432e43d4f33a186c935a42680
  • libcurl3-nss_7.58.0-2ubuntu3.24+tuxcare.els1_amd64.deb
    sha:25bdbd3d963d22e325776746effbcdfe6a27b635
  • libcurl4_7.58.0-2ubuntu3.24+tuxcare.els1_amd64.deb
    sha:076e9f93dc3db4ea5379456e6f315e289b17fdd2
  • libcurl4-doc_7.58.0-2ubuntu3.24+tuxcare.els1_all.deb
    sha:db8ed95609ef47a39d028da7840733acb992bc9d
  • libcurl4-gnutls-dev_7.58.0-2ubuntu3.24+tuxcare.els1_amd64.deb
    sha:862db0a18788cfb7c29675fa4aea7af2888a6b92
  • libcurl4-nss-dev_7.58.0-2ubuntu3.24+tuxcare.els1_amd64.deb
    sha:e60d30b2d47c519e1f56cdf74e05665b1d2eb850
  • libcurl4-openssl-dev_7.58.0-2ubuntu3.24+tuxcare.els1_amd64.deb
    sha:d8003e83a4cc381a121171c6c4ea63653b96502c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.