ELSA-2010-0273

ELSA-2010-0273 - curl security, bug fix and enhancement update

Type:SECURITY
Severity:MODERATE
Release Date:2010-04-05

Description


[7.15.5-9]
- http://curl.haxx.se/docs/adv_20100209.html (#565408)

[7.15.5-8]
- mention lack of IPv6, FTPS and LDAP support while using a socks proxy
(#473128)
- avoid tight loop if an upload connection is broken (#479967)
- add options --ftp-account and --ftp-alternative-to-user to program help
(#517084)
- fix crash when reusing connection after negotiate-auth (#517199)
- support for CRL loading from a PEM file (#532069)

[7.15.5-7]
- sync patch for CVE-2007-0037 with 5.3.Z
Related: #485290

[7.15.5-6]
- fix CVE-2009-2417
Resolves: #516258

[7.15.5-5]
- forwardport one hunk from upstream curl-7.15.1
Related: #485290

[7.15.5-4]
- fix hunk applied to wrong place due to nonzero patch fuzz
Related: #485290

[7.15.5-3]
- fix CVE-2007-0037
Resolves: #485290


Related CVEs


CVE-2010-0734

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 5 (i386) curl-7.15.5-9.el5.src.rpm26d4d47a804b417d028d26d08cffddfbELSA-2013-0983
curl-7.15.5-9.el5.i386.rpm529baec147250dd6d2a8a4c61ef09c94ELSA-2013-0983
curl-devel-7.15.5-9.el5.i386.rpm4cffa93cbcd5cf8cd14451d69180dd07ELSA-2013-0983
Oracle Linux 5 (ia64) curl-7.15.5-9.el5.src.rpm26d4d47a804b417d028d26d08cffddfbELSA-2013-0983
curl-7.15.5-9.el5.ia64.rpm90a5af23df0f9090f5b2784e8533fc11ELSA-2013-0983
curl-devel-7.15.5-9.el5.ia64.rpm684e187d34037c5614fb9da44e3820bfELSA-2013-0983
Oracle Linux 5 (x86_64) curl-7.15.5-9.el5.src.rpm26d4d47a804b417d028d26d08cffddfbELSA-2013-0983
curl-7.15.5-9.el5.i386.rpm529baec147250dd6d2a8a4c61ef09c94ELSA-2013-0983
curl-7.15.5-9.el5.x86_64.rpmf1ab065cdb95dc1ab9ec9a47dfb99a35ELSA-2013-0983
curl-devel-7.15.5-9.el5.i386.rpm4cffa93cbcd5cf8cd14451d69180dd07ELSA-2013-0983
curl-devel-7.15.5-9.el5.x86_64.rpm18391363780869efd83fc0995c200414ELSA-2013-0983



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete