Ubuntu security notices
USN-3993-2: curl vulnerability
USN-3993-2: curl vulnerability curl vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 ESM Ubuntu 12.04 ESM Summary curl could be made to crash if it received a specially crafted data. Software Description curl – HTTP, HTTPS, and FTP client and client libraries Details USN-3993-1 fixed a vulnerability in curl. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: It was discovered that curl incorrectly handled memory when receiving data from a TFTP server. A remote attacker could use this issue to cause curl to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2019-5436) Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM curl – 7.35.0-1ubuntu2.20+esm2 libcurl3 – 7.35.0-1ubuntu2.20+esm2 libcurl3-gnutls – 7.35.0-1ubuntu2.20+esm2 libcurl3-nss [ more… ]