Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.704098
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-4098-1)
Summary:The remote host is missing an update for the Debian 'curl' package(s) announced via the DSA-4098-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'curl' package(s) announced via the DSA-4098-1 advisory.

Vulnerability Insight:
Two vulnerabilities were discovered in cURL, an URL transfer library.

CVE-2018-1000005

Zhouyihai Ding discovered an out-of-bounds read in the code handling HTTP/2 trailers. This issue doesn't affect the oldstable distribution (jessie).

CVE-2018-1000007

Craig de Stigter discovered that authentication data might be leaked to third parties when following HTTP redirects.

For the oldstable distribution (jessie), these problems have been fixed in version 7.38.0-4+deb8u9.

For the stable distribution (stretch), these problems have been fixed in version 7.52.1-5+deb9u4.

We recommend that you upgrade your curl packages.

For the detailed security status of curl please refer to its security tracker page at: [link moved to references]

Affected Software/OS:
'curl' package(s) on Debian 8, Debian 9.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-1000007
Debian Security Information: DSA-4098 (Google Search)
https://www.debian.org/security/2018/dsa-4098
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
https://lists.debian.org/debian-lts-announce/2018/01/msg00038.html
http://www.openwall.com/lists/oss-security/2022/04/27/4
RedHat Security Advisories: RHBA-2019:0327
https://access.redhat.com/errata/RHBA-2019:0327
RedHat Security Advisories: RHSA-2018:3157
https://access.redhat.com/errata/RHSA-2018:3157
RedHat Security Advisories: RHSA-2018:3558
https://access.redhat.com/errata/RHSA-2018:3558
RedHat Security Advisories: RHSA-2019:1543
https://access.redhat.com/errata/RHSA-2019:1543
RedHat Security Advisories: RHSA-2020:0544
https://access.redhat.com/errata/RHSA-2020:0544
RedHat Security Advisories: RHSA-2020:0594
https://access.redhat.com/errata/RHSA-2020:0594
http://www.securitytracker.com/id/1040274
https://usn.ubuntu.com/3554-1/
https://usn.ubuntu.com/3554-2/
CopyrightCopyright (C) 2018 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.