Oval Definition:oval:org.opensuse.security:def:90345
Revision Date:2020-09-02Version:1
Title:Security update for curl (Moderate)
Description:

This update for curl fixes the following issues:

- An application that performs multiple requests with libcurl's multi API and sets the 'CURLOPT_CONNECT_ONLY' option, might in rare circumstances experience that when subsequently using the setup connect-only transfer, libcurl will pick and use the wrong connection and instead pick another one the application has created since then. [bsc#1175109, CVE-2020-8231]
Family:unixClass:patch
Status:Reference(s):1175109
CVE-2020-8231
SUSE-SU-2020:2446-1
Platform(s):SUSE Linux Enterprise Desktop 15 SP1
SUSE Linux Enterprise High Performance Computing 15 SP1
SUSE Linux Enterprise Module for Basesystem 15 SP1
SUSE Linux Enterprise Server 15 SP1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
SUSE Linux Enterprise Storage 6
SUSE Manager Proxy 4.0
SUSE Manager Server 4.0
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP1 is installed
  • AND Package Information
  • curl-7.60.0-3.32.1 is installed
  • OR libcurl-devel-7.60.0-3.32.1 is installed
  • OR libcurl4-7.60.0-3.32.1 is installed
  • OR libcurl4-32bit-7.60.0-3.32.1 is installed
  • BACK