curl-7.61.1-34.el8_10.9

エラータID: AXSA:2025-11629:05

リリース日: 
2025/12/26 Friday - 11:32
題名: 
curl-7.61.1-34.el8_10.9
影響のあるチャネル: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.

Security Fix(es):

* curl: libcurl: Curl out of bounds read for cookie path (CVE-2025-9086)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2025-9086
1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with just a slash as path (`path='/'`). Since this site is not secure, the cookie *should* just be ignored. 4. A bug in the path comparison logic makes curl read outside a heap buffer boundary The bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path. The presumed and correct behavior would be to plainly ignore the second set of the cookie since it was already set as secure on a secure host so overriding it on an insecure host should not be okay.

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. curl-7.61.1-34.el8_10.9.src.rpm
    MD5: f6f5d511440bafd0e1d561a926513ea7
    SHA-256: 85f612b9028769950da9452b15a75a252640ff4795f62cf5a18ee5b4e5992068
    Size: 2.52 MB

Asianux Server 8 for x86_64
  1. curl-7.61.1-34.el8_10.9.x86_64.rpm
    MD5: 3b985126c9cfc3bff44777fb76c80760
    SHA-256: 103f266e6799753848187baa382ee18d7a62eb0fc381643a5d2c3b66e9e063bd
    Size: 353.57 kB
  2. libcurl-7.61.1-34.el8_10.9.i686.rpm
    MD5: 51d7ee79459808505ae704a5abd398e2
    SHA-256: 6b494d329291c74d3da45f4e2c4fb832993a7a408102bda345683ed12d7573cd
    Size: 331.98 kB
  3. libcurl-7.61.1-34.el8_10.9.x86_64.rpm
    MD5: 49ed729223ff8870ec5b5643f31db0c1
    SHA-256: e31e655bd94e85435861a3cc5fdc1c651f5e5d89767cdab84a8f0ce223fb3822
    Size: 304.00 kB
  4. libcurl-devel-7.61.1-34.el8_10.9.i686.rpm
    MD5: 31cafe5693eb69122a5d93b341037517
    SHA-256: d3110e649e6bfacbe3d72a02f29f5c1b5399426bcc25c5f3b58b7bef10025c35
    Size: 835.86 kB
  5. libcurl-devel-7.61.1-34.el8_10.9.x86_64.rpm
    MD5: 5aa47324699e0d9ef6e5d4e809759747
    SHA-256: 7a67915b1d7cd3ad42c4ad34d0009159bbf64b110f589500c224a1a1104d4bbc
    Size: 835.81 kB
  6. libcurl-minimal-7.61.1-34.el8_10.9.i686.rpm
    MD5: 87128dbb2f1ee5f9b4f6641859a93ac8
    SHA-256: e1c8bb65aa456cd51a892a65a6f1dee8f811caa5cac8aa8ec5912edbb2e55a9a
    Size: 316.97 kB
  7. libcurl-minimal-7.61.1-34.el8_10.9.x86_64.rpm
    MD5: 1bcb41cff071460f8aa64d593d1fc5db
    SHA-256: 89db095335788844938b97842918b9d384364bc443731b570fbdb9d7c497099b
    Size: 290.20 kB