curl-7.15.5-9.AXS3
エラータID: AXSA:2010-170:01
cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and Dict servers, using any of the supported protocols. cURL is designed to work without user interaction or any kind of interactivity. cURL offers many useful capabilities, like proxy support, user authentication, FTP upload, HTTP post, and file transfer resume.
Security issues fixed with this release:
CVE-2010-0734
content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that requests automatic decompression, which might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact by sending crafted compressed data to an application that relies on the intended data-length limit.
Fixed bugs:
- http://curl.haxx.se/docs/adv_20100209.html
- avoid tight loop if an upload connection is broken: when uploading a file, if the connection was lost or reset, curl would use 100%CPU and not display an error message; this has been fixed.
- fixed crash (segmentation fault) when reusing connection after negotiate-auth
- sync patch for CVE-2007-0037 with 5.3.Z
Enhancements:
- mention lack of IPv6, FTPS and LDAP support while using a socks proxy:updated the manpage to reflect the lack of support of those protocols with the '--socks4' and '--socks5' options.
- added options --ftp-account and --ftp-alternative-to-user to program help
- now supports CRL (lCertificate Revocation Lists) oading from a PEM (Privacy Enhanced Mail) file
Update packages.
content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that requests automatic decompression, which might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact by sending crafted compressed data to an application that relies on the intended data-length limit.
N/A
Asianux Server 3 for x86
- curl-7.15.5-9.AXS3.i386.rpm
MD5: 4f6afd6072444b6585eb133a1ab2947c
SHA-256: 6bb3af10ede249de8823892a7abdba3430c975e952d1b0d51ea1c9189374d57a
Size: 267.22 kB - curl-devel-7.15.5-9.AXS3.i386.rpm
MD5: 81cecf8e9637c3af58d39fb773a6e703
SHA-256: e90634875bd622a923c5c7dcdc7e999b6c4692c825ba68bfd05ade552680093b
Size: 310.52 kB
Asianux Server 3 for x86_64
- curl-7.15.5-9.AXS3.x86_64.rpm
MD5: 6bb7654b7d3387ddb48d84b778d9d52a
SHA-256: 7856361f86f7e1de8009b2d7e0080d5cf625e075a02f45c89c19867b03544731
Size: 264.59 kB - curl-devel-7.15.5-9.AXS3.x86_64.rpm
MD5: 4ccc02433c2eb24c2162cb03200c1d7b
SHA-256: f20dfdc21ba3059a2dba3059ddb8c5032368546aab0fc5925448f23f613c6113
Size: 318.70 kB