USN-3123-1: curl vulnerabilities
USN-3123-1: curl vulnerabilities Ubuntu Security Notice USN-3123-1 3rd November, 2016 curl vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Several security issues were fixed in curl. Software description curl – HTTP, HTTPS, and FTP client and client libraries Details It was discovered that curl incorrectly reused client certificates whenbuilt with NSS. A remote attacker could possibly use this issue to hijackthe authentication of a TLS connection. (CVE-2016-7141) Nguyen Vu Hoang discovered that curl incorrectly handled escaping certainstrings. A remote attacker could possibly use this issue to cause curl tocrash, resulting in a denial of service, or possibly execute arbitrarycode. (CVE-2016-7167) It was discovered that curl incorrectly handled storing cookies. A remoteattacker could possibly use this issue to inject cookies for arbitrarydomains in the cookie [ more… ]