Oval Definition:oval:org.opensuse.security:def:20120036
Revision Date:2015-11-16Version:1
Title:CVE-2012-0036
Description:
curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows remote attackers to conduct data-injection attacks via a crafted URL, as demonstrated by a CRLF injection attack on the (1) IMAP, (2) POP3, or (3) SMTP protocol.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2012-0036
Platform(s):openSUSE 11.4
openSUSE 12.1
openSUSE 12.1 Update
Product(s):
Definition Synopsis
  • suse114 is installed
  • AND Package Information
  • curl less than 7.21.2-10.11.1
  • OR libcurl-devel less than 7.21.2-10.11.1
  • OR libcurl4-32bit less than 7.21.2-10.11.1
  • OR libcurl4 less than 7.21.2-10.11.1
  • BACK