Oval Definition:oval:org.mitre.oval:def:13672
Revision Date:2014-06-30Version:20
Title:USN-726-2 -- curl regression
Description:USN-726-1 fixed a vulnerability in curl. Due to an incomplete fix, a regression was introduced in Ubuntu 8.10 that caused certain types of URLs to fail. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that curl did not enforce any restrictions when following URL redirects. If a user or automated system were tricked into opening a URL to an untrusted server, an attacker could use redirects to gain access to arbitrary files. This update changes curl behavior to prevent following "file" URLs after a redirect.
Family:unixClass:patch
Status:ACCEPTEDReference(s):USN-726-2
USN-726-2
Platform(s):Ubuntu 8.10
Product(s):curl
Definition Synopsis
  • Ubuntu 8.10 is installed
  • AND Supported architectures section
  • Installed architecture is sparc
  • OR Installed architecture is i386
  • OR Installed architecture is amd64
  • OR Installed architecture is lpia
  • OR Installed architecture is powerpc
  • AND Packages section
  • libcurl4-gnutls-dev DPKG is earlier than 7.18.2-1ubuntu4.3
  • OR libcurl4-openssl-dev DPKG is earlier than 7.18.2-1ubuntu4.3
  • OR libcurl3-gnutls DPKG is earlier than 7.18.2-1ubuntu4.3
  • OR libcurl3-dbg DPKG is earlier than 7.18.2-1ubuntu4.3
  • OR libcurl3 DPKG is earlier than 7.18.2-1ubuntu4.3
  • OR curl DPKG is earlier than 7.18.2-1ubuntu4.3
  • BACK