Oval Definition:oval:com.redhat.rhsa:def:20050875
Revision Date:2005-12-20Version:502
Title:RHSA-2005:875: curl security update (Moderate)
Description:cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and Dict servers, using any of the supported protocols.

Stefan Esser discovered an off-by-one bug in curl. It may be possible to execute arbitrary code on a user's machine if the user can be tricked into executing curl with a carefully crafted URL. The Common Vulnerabilities and Exposures project assigned the name CVE-2005-4077 to this issue.

All users of curl are advised to upgrade to these updated packages, which contain a backported patch that resolves this issue.
Family:unixClass:patch
Status:Reference(s):CVE-2005-4077
RHSA-2005:875-01
Platform(s):Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux 4 is installed
  • AND Package Information
  • curl is earlier than 0:7.12.1-8.rhel4
  • AND curl is signed with Red Hat master key
  • OR
  • curl-devel is earlier than 0:7.12.1-8.rhel4
  • AND curl-devel is signed with Red Hat master key
  • BACK