[CLSA-2024:1710436611] Fix CVE(s): CVE-2023-46218
Type:
security
Severity:
Moderate
Release date:
2024-03-14 17:16:53 UTC
Description:
* SECURITY UPDATE: Insecure cookie domain verification - debian/patches/CVE-2023-46218.patch: lowercase domain names before PSL checks to fix cookie domain validation - CVE-2023-46218
Updated packages:
  • curl_7.58.0-2ubuntu3.24+tuxcare.els3_amd64.deb
    sha:8209379e337bb10ed9198ee040b305deea1d20e0
  • libcurl3-gnutls_7.58.0-2ubuntu3.24+tuxcare.els3_amd64.deb
    sha:20298eeb5b8c91536ef7faa889c76fc2f9e5d627
  • libcurl3-nss_7.58.0-2ubuntu3.24+tuxcare.els3_amd64.deb
    sha:3a85495ca44fcc31814636e6b8f5f7e89b6b0877
  • libcurl4_7.58.0-2ubuntu3.24+tuxcare.els3_amd64.deb
    sha:a4e032915fad16859c2f83984dae94055be939a0
  • libcurl4-doc_7.58.0-2ubuntu3.24+tuxcare.els3_all.deb
    sha:2253dcb6f5e6684a4a8f85b4caae4d1ef07900a4
  • libcurl4-gnutls-dev_7.58.0-2ubuntu3.24+tuxcare.els3_amd64.deb
    sha:e63a93046d7e90087bb1d4592362ca83531da489
  • libcurl4-nss-dev_7.58.0-2ubuntu3.24+tuxcare.els3_amd64.deb
    sha:d6b0b1094f74e9fcd07b80e12f1c5124a33fa932
  • libcurl4-openssl-dev_7.58.0-2ubuntu3.24+tuxcare.els3_amd64.deb
    sha:9f668501d1b43fdc9cd2c81abd4fa3eacb24f7a0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.