Bug 36967 - curl: Multiple issues (4.0)
curl: Multiple issues (4.0)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 4.0
Other Linux
: P3 normal (vote)
: UCS 4.0-1
Assigned To: Moritz Muehlenhoff
Janek Walkenhorst
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-11-24 12:53 CET by Moritz Muehlenhoff
Modified: 2017-10-26 13:54 CEST (History)
0 users

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Moritz Muehlenhoff univentionstaff 2014-11-24 12:53:07 CET
+++ This bug was initially created as a clone of Bug #36468 +++

Information leak in curl_easy_duphandle() (CVE-2014-3707)
Comment 1 Moritz Muehlenhoff univentionstaff 2015-01-08 15:01:32 CET
CVE-2014-8150

When libcurl sends a request to a server via a HTTP proxy, it copies the entire URL into the request and sends if off.

If the given URL contains line feeds and carriage returns those will be sent along to the proxy too, which allows the program to for example send a separate HTTP request injected embedded in the URL.
Comment 2 Moritz Muehlenhoff univentionstaff 2015-02-03 07:42:50 CET
This was fixed during the import of the Wheezy 7.8 point update in Bug 37511
Comment 3 Stefan Gohmann univentionstaff 2015-02-11 10:58:59 CET
UCS 4.0-1 has been released:
 http://docs.univention.de/release-notes-4.0-1-en.html
 http://docs.univention.de/release-notes-4.0-1-de.html

If this error occurs again, please use "Clone This Bug".