curl-7.19.7-26.1.0.1.AXS4
エラータID: AXSA:2011-424:01
リリース日:
2011/12/28 Wednesday - 19:26
題名:
curl-7.19.7-26.1.0.1.AXS4
影響のあるチャネル:
Asianux Server 4 for x86
Asianux Server 4 for x86_64
Severity:
High
Description:
cURL is a tool for getting files from HTTP, FTP, FILE, LDAP, LDAPS, DICT, TELNET and TFTP servers, using any of the supported protocols. cURL is designed to work without user interaction or any kind of interactivity. cURL offers many useful capabilities, like proxy support, user authentication, FTP upload, HTTP post, and file transfer resume.
Security issues fixed with this release:
CVE-2011-2192
The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.
解決策:
Update packages.
CVE:
CVE-2011-2192
The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.
The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.
追加情報:
From Asianux Server 4 SP1.
ダウンロード:
SRPMS
- curl-7.19.7-26.1.0.1.AXS4.src.rpm
MD5: eea7007a71ec1acdf11af3a3b3ba7326
SHA-256: 599dfdb3e2fa131a937512547292ca48e48e8bcd1bc4225b86a2d034be32d69c
Size: 1.98 MB
Asianux Server 4 for x86
- curl-7.19.7-26.1.0.1.AXS4.i686.rpm
MD5: 555726adcb708ddf8058c623f5da112c
SHA-256: d7a59a6232f826b04337f8f05febc2e4280c38a051a6e8e631e81378c232d97b
Size: 190.90 kB - libcurl-7.19.7-26.1.0.1.AXS4.i686.rpm
MD5: 8abe33713961bd42506d3019e81b783e
SHA-256: a34ae387e4c00663824a949cb4c0628a335de47aa554b7a379b7cc6407073784
Size: 168.55 kB - libcurl-devel-7.19.7-26.1.0.1.AXS4.i686.rpm
MD5: 48eb00d3eef21751e5de4b4d0d575a58
SHA-256: 7735a01870a5fe7898d385db145ea4e43f24623ee6c2f80009f7e8057a052fdd
Size: 241.82 kB
Asianux Server 4 for x86_64
- curl-7.19.7-26.1.0.1.AXS4.x86_64.rpm
MD5: 591986e749feed89d0c94e673722d109
SHA-256: c64952b729d41bb8551f21ad8ebefa9ab1d8c232449a18635cba3f7b8a4c7963
Size: 190.49 kB - libcurl-7.19.7-26.1.0.1.AXS4.x86_64.rpm
MD5: 0175b58faeeaf1b09caca743ec41811e
SHA-256: 64f7ae60b7923ca61774788d9c5a864613bde5f1fef093359c903aeab1b13d9f
Size: 161.53 kB - libcurl-devel-7.19.7-26.1.0.1.AXS4.x86_64.rpm
MD5: 358792a88daaa14a9ccd15c0763dabea
SHA-256: cf0f88234386da834f8410531abf1f2d4a444b60898a92bde4c97953fa465229
Size: 241.39 kB - libcurl-7.19.7-26.1.0.1.AXS4.i686.rpm
MD5: 8abe33713961bd42506d3019e81b783e
SHA-256: a34ae387e4c00663824a949cb4c0628a335de47aa554b7a379b7cc6407073784
Size: 168.55 kB - libcurl-devel-7.19.7-26.1.0.1.AXS4.i686.rpm
MD5: 48eb00d3eef21751e5de4b4d0d575a58
SHA-256: 7735a01870a5fe7898d385db145ea4e43f24623ee6c2f80009f7e8057a052fdd
Size: 241.82 kB