Ubuntu security notices
USN-3554-1: curl vulnerabilities
USN-3554-1: curl vulnerabilities Ubuntu Security Notice USN-3554-1 31st January, 2018 curl vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in curl. Software description curl – HTTP, HTTPS, and FTP client and client libraries Details It was discovered that curl incorrectly handled certain data. An attackercould possibly use this to cause a denial of service or even to get accessto sensitive data. This issue only affected Ubuntu 16.04 LTS and Ubuntu 17.10. It was discovered that curl could accidentally leak authentication data.An attacker could possibly use this to get access to sensitive information.(CVE-2018-1000007) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 17.10: libcurl3-nss 7.55.1-1ubuntu2.3 curl 7.55.1-1ubuntu2.3 libcurl3-gnutls 7.55.1-1ubuntu2.3 libcurl3 7.55.1-1ubuntu2.3 Ubuntu 16.04 LTS: libcurl3-nss [ more… ]