ELSA-2023-2650

ELSA-2023-2650 - curl security update

Type:SECURITY
Impact:MODERATE
Release Date:2023-05-17

Description


[7.76.1-23.el9_2.1]
- fix FTP too eager connection reuse (CVE-2023-27535)

[7.76.1-23]
- fix HTTP multi-header compression denial of service (CVE-2023-23916)

[7.76.1-22]
- smb/telnet: fix use-after-free when HTTP proxy denies tunnel (CVE-2022-43552)

[7.76.1-21]
- fix POST following PUT confusion (CVE-2022-32221)

[7.76.1-20]
- control code in cookie denial of service (CVE-2022-35252)


Related CVEs


CVE-2023-27535

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) curl-7.76.1-23.el9.src.rpm257f15bb24cfbc289a0d2a3096bf74aafec5290a34ad96b3668bee03a103341e-ol9_aarch64_appstream
curl-7.76.1-23.el9.src.rpm257f15bb24cfbc289a0d2a3096bf74aafec5290a34ad96b3668bee03a103341e-ol9_aarch64_appstream_developer
curl-7.76.1-23.el9.src.rpm257f15bb24cfbc289a0d2a3096bf74aafec5290a34ad96b3668bee03a103341e-ol9_aarch64_baseos_developer
curl-7.76.1-23.el9.src.rpm257f15bb24cfbc289a0d2a3096bf74aafec5290a34ad96b3668bee03a103341e-ol9_aarch64_baseos_latest
curl-7.76.1-23.el9.src.rpm257f15bb24cfbc289a0d2a3096bf74aafec5290a34ad96b3668bee03a103341e-ol9_aarch64_u2_baseos_base
curl-7.76.1-23.el9_2.1.src.rpmf02f67507719346b08cd49111e502bf6541a9e171cf34e34b227f6d89d89b4f7-ol9_aarch64_appstream
curl-7.76.1-23.el9_2.1.src.rpmf02f67507719346b08cd49111e502bf6541a9e171cf34e34b227f6d89d89b4f7-ol9_aarch64_baseos_latest
curl-7.76.1-23.el9_2.1.src.rpmf02f67507719346b08cd49111e502bf6541a9e171cf34e34b227f6d89d89b4f7-ol9_aarch64_u2_baseos_patch
curl-7.76.1-23.el9.aarch64.rpma371b258f1a2d7a3a4595f204056760a4ad040150042f9adb410417db8ab9c46-ol9_aarch64_baseos_developer
curl-7.76.1-23.el9.aarch64.rpma371b258f1a2d7a3a4595f204056760a4ad040150042f9adb410417db8ab9c46-ol9_aarch64_baseos_latest
curl-7.76.1-23.el9.aarch64.rpma371b258f1a2d7a3a4595f204056760a4ad040150042f9adb410417db8ab9c46-ol9_aarch64_u2_baseos_base
curl-7.76.1-23.el9_2.1.aarch64.rpmca248bc85bb55cdaf5e2628a958dc299b834b0518cba1177ab96ace59ef54c72-ol9_aarch64_baseos_latest
curl-7.76.1-23.el9_2.1.aarch64.rpmca248bc85bb55cdaf5e2628a958dc299b834b0518cba1177ab96ace59ef54c72-ol9_aarch64_u2_baseos_patch
curl-minimal-7.76.1-23.el9.aarch64.rpmdefb4e1f4aad5796c35d0c80323423bc83a6d9d766e773db980db385e61fbbc9-ol9_aarch64_baseos_developer
curl-minimal-7.76.1-23.el9.aarch64.rpmdefb4e1f4aad5796c35d0c80323423bc83a6d9d766e773db980db385e61fbbc9-ol9_aarch64_baseos_latest
curl-minimal-7.76.1-23.el9.aarch64.rpmdefb4e1f4aad5796c35d0c80323423bc83a6d9d766e773db980db385e61fbbc9-ol9_aarch64_u2_baseos_base
curl-minimal-7.76.1-23.el9_2.1.aarch64.rpm374ac9677349ddd1581e22c14da7d3be6f6e22ee97b0dd7bfab491e504b3050b-ol9_aarch64_baseos_latest
curl-minimal-7.76.1-23.el9_2.1.aarch64.rpm374ac9677349ddd1581e22c14da7d3be6f6e22ee97b0dd7bfab491e504b3050b-ol9_aarch64_u2_baseos_patch
libcurl-7.76.1-23.el9.aarch64.rpm9f7dad0d1ad2de6f8db4c7a6cde157d072bf6b49ec941e9a57f85da10df0c12f-ol9_aarch64_baseos_developer
libcurl-7.76.1-23.el9.aarch64.rpm9f7dad0d1ad2de6f8db4c7a6cde157d072bf6b49ec941e9a57f85da10df0c12f-ol9_aarch64_baseos_latest
libcurl-7.76.1-23.el9.aarch64.rpm9f7dad0d1ad2de6f8db4c7a6cde157d072bf6b49ec941e9a57f85da10df0c12f-ol9_aarch64_u2_baseos_base
libcurl-7.76.1-23.el9_2.1.aarch64.rpm93fc54a9a143ee37bd475ed769180981f6741258b3c54a01956374237fcde835-ol9_aarch64_baseos_latest
libcurl-7.76.1-23.el9_2.1.aarch64.rpm93fc54a9a143ee37bd475ed769180981f6741258b3c54a01956374237fcde835-ol9_aarch64_u2_baseos_patch
libcurl-devel-7.76.1-23.el9.aarch64.rpm84cd3e94572c533b404d9066574841b38ab4188158e91412b50dd29128bf39b5-ol9_aarch64_appstream
libcurl-devel-7.76.1-23.el9.aarch64.rpm84cd3e94572c533b404d9066574841b38ab4188158e91412b50dd29128bf39b5-ol9_aarch64_appstream_developer
libcurl-devel-7.76.1-23.el9_2.1.aarch64.rpmaa302d4ca559f80f561f6248af311588a544f3cdbbcda5bab6071333bb800e39-ol9_aarch64_appstream
libcurl-minimal-7.76.1-23.el9.aarch64.rpm15eb81e834d93f6d33d1006e9d53ab8aec98855e81be7dfeeb0b86899ed8cacd-ol9_aarch64_baseos_developer
libcurl-minimal-7.76.1-23.el9.aarch64.rpm15eb81e834d93f6d33d1006e9d53ab8aec98855e81be7dfeeb0b86899ed8cacd-ol9_aarch64_baseos_latest
libcurl-minimal-7.76.1-23.el9.aarch64.rpm15eb81e834d93f6d33d1006e9d53ab8aec98855e81be7dfeeb0b86899ed8cacd-ol9_aarch64_u2_baseos_base
libcurl-minimal-7.76.1-23.el9_2.1.aarch64.rpmad54c0506f1e93424560899980dcb73cf17c763051640dfcf450835594b442cc-ol9_aarch64_baseos_latest
libcurl-minimal-7.76.1-23.el9_2.1.aarch64.rpmad54c0506f1e93424560899980dcb73cf17c763051640dfcf450835594b442cc-ol9_aarch64_u2_baseos_patch
Oracle Linux 9 (x86_64) curl-7.76.1-23.el9.src.rpm257f15bb24cfbc289a0d2a3096bf74aafec5290a34ad96b3668bee03a103341e-ol9_x86_64_appstream
curl-7.76.1-23.el9.src.rpm257f15bb24cfbc289a0d2a3096bf74aafec5290a34ad96b3668bee03a103341e-ol9_x86_64_appstream_developer
curl-7.76.1-23.el9.src.rpm257f15bb24cfbc289a0d2a3096bf74aafec5290a34ad96b3668bee03a103341e-ol9_x86_64_baseos_developer
curl-7.76.1-23.el9.src.rpm257f15bb24cfbc289a0d2a3096bf74aafec5290a34ad96b3668bee03a103341e-ol9_x86_64_baseos_latest
curl-7.76.1-23.el9.src.rpm257f15bb24cfbc289a0d2a3096bf74aafec5290a34ad96b3668bee03a103341e-ol9_x86_64_u2_baseos_base
curl-7.76.1-23.el9_2.1.src.rpmf02f67507719346b08cd49111e502bf6541a9e171cf34e34b227f6d89d89b4f7-ol9_x86_64_appstream
curl-7.76.1-23.el9_2.1.src.rpmf02f67507719346b08cd49111e502bf6541a9e171cf34e34b227f6d89d89b4f7-ol9_x86_64_baseos_latest
curl-7.76.1-23.el9_2.1.src.rpmf02f67507719346b08cd49111e502bf6541a9e171cf34e34b227f6d89d89b4f7-ol9_x86_64_u2_baseos_patch
curl-7.76.1-23.el9.x86_64.rpm1c41a035b90169490e37d8eb303bfa029a27732015f859edbaef89d46ab2daaf-ol9_x86_64_baseos_developer
curl-7.76.1-23.el9.x86_64.rpm1c41a035b90169490e37d8eb303bfa029a27732015f859edbaef89d46ab2daaf-ol9_x86_64_baseos_latest
curl-7.76.1-23.el9.x86_64.rpm1c41a035b90169490e37d8eb303bfa029a27732015f859edbaef89d46ab2daaf-ol9_x86_64_u2_baseos_base
curl-7.76.1-23.el9_2.1.x86_64.rpm2773d7ad60b52304cef4d1bad8f55b567b5565153ce595ee21f9cd7741df5a8c-ol9_x86_64_baseos_latest
curl-7.76.1-23.el9_2.1.x86_64.rpm2773d7ad60b52304cef4d1bad8f55b567b5565153ce595ee21f9cd7741df5a8c-ol9_x86_64_u2_baseos_patch
curl-minimal-7.76.1-23.el9.x86_64.rpm32bad0da2bc70901b11aa52a791cf7192ffbc4bc6b658993fd2528ee41aa2f57-ol9_x86_64_baseos_developer
curl-minimal-7.76.1-23.el9.x86_64.rpm32bad0da2bc70901b11aa52a791cf7192ffbc4bc6b658993fd2528ee41aa2f57-ol9_x86_64_baseos_latest
curl-minimal-7.76.1-23.el9.x86_64.rpm32bad0da2bc70901b11aa52a791cf7192ffbc4bc6b658993fd2528ee41aa2f57-ol9_x86_64_u2_baseos_base
curl-minimal-7.76.1-23.el9_2.1.x86_64.rpm12d47f08af36cf132e20db4a5bd11bb042d79df44333c6a3f8b71afbeceaad63-ol9_x86_64_baseos_latest
curl-minimal-7.76.1-23.el9_2.1.x86_64.rpm12d47f08af36cf132e20db4a5bd11bb042d79df44333c6a3f8b71afbeceaad63-ol9_x86_64_u2_baseos_patch
libcurl-7.76.1-23.el9.i686.rpm45cec84d0619baa6f695d5af797079a36e44d52ae9c3b7f04cfe64c88cc030ba-ol9_x86_64_baseos_developer
libcurl-7.76.1-23.el9.i686.rpm45cec84d0619baa6f695d5af797079a36e44d52ae9c3b7f04cfe64c88cc030ba-ol9_x86_64_baseos_latest
libcurl-7.76.1-23.el9.i686.rpm45cec84d0619baa6f695d5af797079a36e44d52ae9c3b7f04cfe64c88cc030ba-ol9_x86_64_u2_baseos_base
libcurl-7.76.1-23.el9.x86_64.rpm1f8f6195c4bd7412f050c6e7fe33bd585493cf04b87fd04f9f27ae02ec52a767-ol9_x86_64_baseos_developer
libcurl-7.76.1-23.el9.x86_64.rpm1f8f6195c4bd7412f050c6e7fe33bd585493cf04b87fd04f9f27ae02ec52a767-ol9_x86_64_baseos_latest
libcurl-7.76.1-23.el9.x86_64.rpm1f8f6195c4bd7412f050c6e7fe33bd585493cf04b87fd04f9f27ae02ec52a767-ol9_x86_64_u2_baseos_base
libcurl-7.76.1-23.el9_2.1.i686.rpmc07e016ec9ac9858e7fd2e399fb40e2750621d53676fcc60fa85c1fd01667342-ol9_x86_64_baseos_latest
libcurl-7.76.1-23.el9_2.1.i686.rpmc07e016ec9ac9858e7fd2e399fb40e2750621d53676fcc60fa85c1fd01667342-ol9_x86_64_u2_baseos_patch
libcurl-7.76.1-23.el9_2.1.x86_64.rpme9be89c3eddbcee3bacf89538a0338ef3310bb26cfae25cfbfe3f346c80d27f2-ol9_x86_64_baseos_latest
libcurl-7.76.1-23.el9_2.1.x86_64.rpme9be89c3eddbcee3bacf89538a0338ef3310bb26cfae25cfbfe3f346c80d27f2-ol9_x86_64_u2_baseos_patch
libcurl-devel-7.76.1-23.el9.i686.rpm1578605964e1d2899c0d9cf353513356849b4d43d3dcac3ec5c3f370098f3f42-ol9_x86_64_appstream
libcurl-devel-7.76.1-23.el9.i686.rpm1578605964e1d2899c0d9cf353513356849b4d43d3dcac3ec5c3f370098f3f42-ol9_x86_64_appstream_developer
libcurl-devel-7.76.1-23.el9.x86_64.rpma22a9d3d7f3e92567d369f968b57659cb3099e68f6ae71eca30cd382a1cb82cd-ol9_x86_64_appstream
libcurl-devel-7.76.1-23.el9.x86_64.rpma22a9d3d7f3e92567d369f968b57659cb3099e68f6ae71eca30cd382a1cb82cd-ol9_x86_64_appstream_developer
libcurl-devel-7.76.1-23.el9_2.1.i686.rpma5871e3d9eb0820b65e49e31b4dccfc9ab94896dcad56e135e5082c20af22144-ol9_x86_64_appstream
libcurl-devel-7.76.1-23.el9_2.1.x86_64.rpmef6e400f8b7a232067c47b7650f4a5d461396aecc64cebf147347be78fae506c-ol9_x86_64_appstream
libcurl-minimal-7.76.1-23.el9.i686.rpm8df62f6e80b3118f7f46547d5610fdc012f8ca12b3479325c3f00f160ad47924-ol9_x86_64_baseos_developer
libcurl-minimal-7.76.1-23.el9.i686.rpm8df62f6e80b3118f7f46547d5610fdc012f8ca12b3479325c3f00f160ad47924-ol9_x86_64_baseos_latest
libcurl-minimal-7.76.1-23.el9.i686.rpm8df62f6e80b3118f7f46547d5610fdc012f8ca12b3479325c3f00f160ad47924-ol9_x86_64_u2_baseos_base
libcurl-minimal-7.76.1-23.el9.x86_64.rpmb806bc8028b348b4b5fc99777f5bc8f5d52b16093537c8cdfdde0622af257576-ol9_x86_64_baseos_developer
libcurl-minimal-7.76.1-23.el9.x86_64.rpmb806bc8028b348b4b5fc99777f5bc8f5d52b16093537c8cdfdde0622af257576-ol9_x86_64_baseos_latest
libcurl-minimal-7.76.1-23.el9.x86_64.rpmb806bc8028b348b4b5fc99777f5bc8f5d52b16093537c8cdfdde0622af257576-ol9_x86_64_u2_baseos_base
libcurl-minimal-7.76.1-23.el9_2.1.i686.rpm324754dada46b56467c7c404be3175b4f34d709586c60fc4ac67992ada86fda2-ol9_x86_64_baseos_latest
libcurl-minimal-7.76.1-23.el9_2.1.i686.rpm324754dada46b56467c7c404be3175b4f34d709586c60fc4ac67992ada86fda2-ol9_x86_64_u2_baseos_patch
libcurl-minimal-7.76.1-23.el9_2.1.x86_64.rpm90e579c6fb6fec4ed56d33b801d33d2658a0a4637174551a829d0a1d638d48a0-ol9_x86_64_baseos_latest
libcurl-minimal-7.76.1-23.el9_2.1.x86_64.rpm90e579c6fb6fec4ed56d33b801d33d2658a0a4637174551a829d0a1d638d48a0-ol9_x86_64_u2_baseos_patch



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete