UbuntuUpdates.org

Bugs fixes in "curl"

Origin Bug number Title Date fixed
CVE CVE-2024-2398 HTTP/2 push headers memory-leak 2024-04-29
CVE CVE-2024-2004 Usage of disabled protocol 2024-04-29
CVE CVE-2024-2398 HTTP/2 push headers memory-leak 2024-03-27
CVE CVE-2024-2398 HTTP/2 push headers memory-leak 2024-03-27
CVE CVE-2024-2398 HTTP/2 push headers memory-leak 2024-03-27
CVE CVE-2024-2398 HTTP/2 push headers memory-leak 2024-03-27
CVE CVE-2023-46218 curl: cookie mixed case PSL bypass 2023-12-06
CVE CVE-2023-46218 curl: cookie mixed case PSL bypass 2023-12-06
CVE CVE-2023-46218 curl: cookie mixed case PSL bypass 2023-12-06
CVE CVE-2023-46218 curl: cookie mixed case PSL bypass 2023-12-06
Launchpad 2028170 curl 7.81.0-1ubuntu1.11 fails verifying proper ssl cert w/ subj-alt-name 2023-07-19
Launchpad 2028170 curl 7.81.0-1ubuntu1.11 fails verifying proper ssl cert w/ subj-alt-name 2023-07-19
CVE CVE-2023-28322 An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOP 2023-07-19
CVE CVE-2023-28321 An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject 2023-07-19
CVE CVE-2023-28322 An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOP 2023-07-19
CVE CVE-2023-28321 An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject 2023-07-19
CVE CVE-2023-28322 An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOP 2023-07-19
CVE CVE-2023-28321 An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject 2023-07-19
CVE CVE-2023-28322 An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOP 2023-07-19
CVE CVE-2023-28321 An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject 2023-07-19



About   -   Send Feedback to @ubuntu_updates