Oval Definition:oval:org.opensuse.security:def:73816
Revision Date:2021-05-26Version:1
Title:Security update for curl (Moderate)
Description:

This update for curl fixes the following issues:

- CVE-2021-22898: Fixed curl TELNET stack contents disclosure (bsc#1186114). - Allow partial chain verification [jsc#SLE-17956] * Have intermediate certificates in the trust store be treated as trust-anchors, in the same way as self-signed root CA certificates are. This allows users to verify servers using the intermediate cert only, instead of needing the whole chain. * Set FLAG_TRUSTED_FIRST unconditionally. * Do not check partial chains with CRL check.
Family:unixClass:patch
Status:Reference(s):1141844
1174052
1175070
1175071
1175074
1186114
CVE-2019-13616
CVE-2020-11984
CVE-2020-11993
CVE-2020-9490
CVE-2021-22898
SUSE-SU-2020:3261-1
SUSE-SU-2021:1762-1
Platform(s):SUSE Linux Enterprise Desktop 15 SP3
SUSE Linux Enterprise High Performance Computing 15 SP3
SUSE Linux Enterprise Module for Basesystem 15 SP3
SUSE Linux Enterprise Module for Desktop Applications 15 SP2
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server for SAP Applications 15 SP3
SUSE Manager Proxy 4.2
SUSE Manager Server 4.2
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2 is installed
  • AND Package Information
  • apache2-2.4.43-3.5 is installed
  • OR apache2-event-2.4.43-3.5 is installed
  • OR apache2-example-pages-2.4.43-3.5 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Desktop Applications 15 SP2 is installed
  • AND Package Information
  • SDL-1.2.15-3.12 is installed
  • OR libSDL-1_2-0-1.2.15-3.12 is installed
  • OR libSDL-devel-1.2.15-3.12 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP3 is installed
  • AND Package Information
  • curl-7.66.0-4.17.1 is installed
  • OR libcurl-devel-7.66.0-4.17.1 is installed
  • OR libcurl4-7.66.0-4.17.1 is installed
  • OR libcurl4-32bit-7.66.0-4.17.1 is installed
  • BACK