ALT-BU-2018-3148-1
Branch c7.1 update bulletin.
Closed bugs
Некорректно указаны пути к модулям ldb
Closed vulnerabilities
BDU:2016-01705
Уязвимость файловой системы Samba, позволяющая нарушителю подменить протоколы SMB2 и SMB3 серверов
BDU:2017-01262
Уязвимость сетевой файловой системы Samba, позволяющая выполнить произвольный код
BDU:2018-00367
Уязвимость пакета программ сетевого взаимодействия Samba, связанная с отсутствием проверки входных данных, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2018-00368
Уязвимость сервера LDAP пакета программ сетевого взаимодействия Samba, позволяющая нарушителю изменять пароли других пользователей
BDU:2019-00223
Уязвимость пакета программ для сетевого взаимодействия Samba, связанная с отсутствием подписи SMB-трафика, позволяющая нарушителю реализовать атаку «человек посередине»
BDU:2019-00224
Уязвимость пакета программ для сетевого взаимодействия Samba, связанная с отсутствием требования подписи и шифрования SMB-трафика при использовании перенаправлений DFS, позволяющая нарушителю реализовать атаку «человек посередине»
BDU:2021-01274
Уязвимость службы NETLOGON пакета программ сетевого взаимодействия Samba, связанная с недостатках элементов безопасности, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность
BDU:2021-01275
Уязвимость функции ncacn_np пакета программ сетевого взаимодействия Samba, связанная с недостатками элементов безопасности, позволяющая нарушителю оказать воздействие на целостность данных
BDU:2021-01276
Уязвимость реализации DCE/RPC пакета программ сетевого взаимодействия Samba, связанная с раскрытием информации, позволяющая нарушителю оказать воздействие на целостность данных
BDU:2021-01289
Уязвимость парсера ndr_pull_dnsp_name пакета программ сетевого взаимодействия Samba, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01290
Уязвимость пакета программ сетевого взаимодействия Samba, связанная с недостатками в механизме криптографической защиты, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность
BDU:2021-01291
Уязвимость библиотеки LDAP пакета программ сетевого взаимодействия Samba, связанная с недостатках элементов безопасности, позволяющая нарушителю оказать воздействие на целостность данных
BDU:2021-01292
Уязвимость реализации протокола SMB1 пакета программ сетевого взаимодействия Samba, связанная с недостатками элементов безопасности, позволяющая нарушителю оказать воздействие на целостность данных
BDU:2021-01294
Уязвимость реализации NTLMSSP пакета программ сетевого взаимодействия Samba, связанная с недостатках элементов безопасности, позволяющая нарушителю оказать воздействие на целостность данных
BDU:2021-01316
Уязвимость протокола MS-SAMR и MS-LSAD пакета программ сетевого взаимодействия Samba, связанная с недостатками элементов безопасности, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01421
Уязвимость пакета программ сетевого взаимодействия Samba, связанная с одновременным выполнением с использованием общего ресурса с неправильной синхронизацией, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01422
Уязвимость реализации протокола SMB1 пакета программ сетевого взаимодействия Samba, связанная с использованием области памяти после её освобождения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01424
Уязвимость функции _krb5_extract_ticket() пакета программ сетевого взаимодействия Samba, связанная с недостатком механизма проверки подлинности данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01425
Уязвимость реализации протокола Kerberos пакета программ сетевого взаимодействия Samba, связанная с недостатком механизма контроля привилегий и средств управления доступом, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01433
Уязвимость реализации протокола SMB1 пакета программ сетевого взаимодействия Samba, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность
BDU:2021-01435
Уязвимость пакета программ сетевого взаимодействия Samba, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным
Modified: 2024-11-21
CVE-2015-5370
Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not properly implement the DCE-RPC layer, which allows remote attackers to perform protocol-downgrade attacks, cause a denial of service (application crash or CPU consumption), or possibly execute arbitrary code on a client system via unspecified vectors.
- http://badlock.org/
- http://badlock.org/
- FEDORA-2016-be53260726
- FEDORA-2016-be53260726
- FEDORA-2016-48b3761baa
- FEDORA-2016-48b3761baa
- FEDORA-2016-383fce04e2
- FEDORA-2016-383fce04e2
- SUSE-SU-2016:1022
- SUSE-SU-2016:1022
- SUSE-SU-2016:1023
- SUSE-SU-2016:1023
- SUSE-SU-2016:1024
- SUSE-SU-2016:1024
- openSUSE-SU-2016:1025
- openSUSE-SU-2016:1025
- SUSE-SU-2016:1028
- SUSE-SU-2016:1028
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1107
- openSUSE-SU-2016:1107
- RHSA-2016:0611
- RHSA-2016:0611
- RHSA-2016:0612
- RHSA-2016:0612
- RHSA-2016:0613
- RHSA-2016:0613
- RHSA-2016:0614
- RHSA-2016:0614
- RHSA-2016:0618
- RHSA-2016:0618
- RHSA-2016:0619
- RHSA-2016:0619
- RHSA-2016:0620
- RHSA-2016:0620
- RHSA-2016:0624
- RHSA-2016:0624
- DSA-3548
- DSA-3548
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 1035533
- 1035533
- SSA:2016-106-02
- SSA:2016-106-02
- USN-2950-1
- USN-2950-1
- USN-2950-2
- USN-2950-2
- USN-2950-3
- USN-2950-3
- USN-2950-4
- USN-2950-4
- USN-2950-5
- USN-2950-5
- https://bto.bluecoat.com/security-advisory/sa122
- https://bto.bluecoat.com/security-advisory/sa122
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05162399
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05162399
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/security/CVE-2015-5370.html
- https://www.samba.org/samba/security/CVE-2015-5370.html
Modified: 2024-11-21
CVE-2016-2110
The NTLMSSP authentication implementation in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 allows man-in-the-middle attackers to perform protocol-downgrade attacks by modifying the client-server data stream to remove application-layer flags or encryption settings, as demonstrated by clearing the NTLMSSP_NEGOTIATE_SEAL or NTLMSSP_NEGOTIATE_SIGN option to disrupt LDAP security.
- http://badlock.org/
- http://badlock.org/
- FEDORA-2016-be53260726
- FEDORA-2016-be53260726
- FEDORA-2016-48b3761baa
- FEDORA-2016-48b3761baa
- FEDORA-2016-383fce04e2
- FEDORA-2016-383fce04e2
- SUSE-SU-2016:1022
- SUSE-SU-2016:1022
- SUSE-SU-2016:1023
- SUSE-SU-2016:1023
- SUSE-SU-2016:1024
- SUSE-SU-2016:1024
- openSUSE-SU-2016:1025
- openSUSE-SU-2016:1025
- SUSE-SU-2016:1028
- SUSE-SU-2016:1028
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1064
- SUSE-SU-2016:1105
- SUSE-SU-2016:1105
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1107
- openSUSE-SU-2016:1107
- openSUSE-SU-2016:1440
- openSUSE-SU-2016:1440
- RHSA-2016:0611
- RHSA-2016:0611
- RHSA-2016:0612
- RHSA-2016:0612
- RHSA-2016:0613
- RHSA-2016:0613
- RHSA-2016:0614
- RHSA-2016:0614
- RHSA-2016:0618
- RHSA-2016:0618
- RHSA-2016:0619
- RHSA-2016:0619
- RHSA-2016:0620
- RHSA-2016:0620
- RHSA-2016:0621
- RHSA-2016:0621
- RHSA-2016:0623
- RHSA-2016:0623
- RHSA-2016:0624
- RHSA-2016:0624
- RHSA-2016:0625
- RHSA-2016:0625
- DSA-3548
- DSA-3548
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 1035533
- 1035533
- SSA:2016-106-02
- SSA:2016-106-02
- USN-2950-1
- USN-2950-1
- USN-2950-2
- USN-2950-2
- USN-2950-3
- USN-2950-3
- USN-2950-4
- USN-2950-4
- USN-2950-5
- USN-2950-5
- https://bto.bluecoat.com/security-advisory/sa122
- https://bto.bluecoat.com/security-advisory/sa122
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05087821
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05087821
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05082964
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05082964
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05162399
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05162399
- GLSA-201612-47
- GLSA-201612-47
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/security/CVE-2016-2110.html
- https://www.samba.org/samba/security/CVE-2016-2110.html
Modified: 2024-11-21
CVE-2016-2111
The NETLOGON service in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2, when a domain controller is configured, allows remote attackers to spoof the computer name of a secure channel's endpoint, and obtain sensitive session information, by running a crafted application and leveraging the ability to sniff network traffic, a related issue to CVE-2015-0005.
- http://badlock.org/
- http://badlock.org/
- FEDORA-2016-be53260726
- FEDORA-2016-be53260726
- FEDORA-2016-48b3761baa
- FEDORA-2016-48b3761baa
- FEDORA-2016-383fce04e2
- FEDORA-2016-383fce04e2
- SUSE-SU-2016:1022
- SUSE-SU-2016:1022
- SUSE-SU-2016:1023
- SUSE-SU-2016:1023
- SUSE-SU-2016:1024
- SUSE-SU-2016:1024
- openSUSE-SU-2016:1025
- openSUSE-SU-2016:1025
- SUSE-SU-2016:1028
- SUSE-SU-2016:1028
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1064
- SUSE-SU-2016:1105
- SUSE-SU-2016:1105
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1107
- openSUSE-SU-2016:1107
- RHSA-2016:0611
- RHSA-2016:0611
- RHSA-2016:0612
- RHSA-2016:0612
- RHSA-2016:0613
- RHSA-2016:0613
- RHSA-2016:0614
- RHSA-2016:0614
- RHSA-2016:0618
- RHSA-2016:0618
- RHSA-2016:0619
- RHSA-2016:0619
- RHSA-2016:0620
- RHSA-2016:0620
- RHSA-2016:0621
- RHSA-2016:0621
- RHSA-2016:0623
- RHSA-2016:0623
- RHSA-2016:0624
- RHSA-2016:0624
- RHSA-2016:0625
- RHSA-2016:0625
- DSA-3548
- DSA-3548
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 1035533
- 1035533
- SSA:2016-106-02
- SSA:2016-106-02
- USN-2950-1
- USN-2950-1
- USN-2950-2
- USN-2950-2
- USN-2950-3
- USN-2950-3
- USN-2950-4
- USN-2950-4
- USN-2950-5
- USN-2950-5
- https://bto.bluecoat.com/security-advisory/sa122
- https://bto.bluecoat.com/security-advisory/sa122
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05087821
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05087821
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05082964
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05082964
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05162399
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05162399
- GLSA-201612-47
- GLSA-201612-47
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/security/CVE-2016-2111.html
- https://www.samba.org/samba/security/CVE-2016-2111.html
Modified: 2024-11-21
CVE-2016-2112
The bundled LDAP client library in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "client ldap sasl wrapping" setting, which allows man-in-the-middle attackers to perform LDAP protocol-downgrade attacks by modifying the client-server data stream.
- http://badlock.org/
- http://badlock.org/
- FEDORA-2016-be53260726
- FEDORA-2016-be53260726
- FEDORA-2016-48b3761baa
- FEDORA-2016-48b3761baa
- FEDORA-2016-383fce04e2
- FEDORA-2016-383fce04e2
- SUSE-SU-2016:1022
- SUSE-SU-2016:1022
- SUSE-SU-2016:1023
- SUSE-SU-2016:1023
- SUSE-SU-2016:1024
- SUSE-SU-2016:1024
- openSUSE-SU-2016:1025
- openSUSE-SU-2016:1025
- SUSE-SU-2016:1028
- SUSE-SU-2016:1028
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1107
- openSUSE-SU-2016:1107
- RHSA-2016:0611
- RHSA-2016:0611
- RHSA-2016:0612
- RHSA-2016:0612
- RHSA-2016:0613
- RHSA-2016:0613
- RHSA-2016:0614
- RHSA-2016:0614
- RHSA-2016:0618
- RHSA-2016:0618
- RHSA-2016:0619
- RHSA-2016:0619
- RHSA-2016:0620
- RHSA-2016:0620
- RHSA-2016:0624
- RHSA-2016:0624
- DSA-3548
- DSA-3548
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 1035533
- 1035533
- SSA:2016-106-02
- SSA:2016-106-02
- USN-2950-1
- USN-2950-1
- USN-2950-2
- USN-2950-2
- USN-2950-3
- USN-2950-3
- USN-2950-4
- USN-2950-4
- USN-2950-5
- USN-2950-5
- https://bto.bluecoat.com/security-advisory/sa122
- https://bto.bluecoat.com/security-advisory/sa122
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05087821
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05087821
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05082964
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05082964
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05162399
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05162399
- GLSA-201612-47
- GLSA-201612-47
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/security/CVE-2016-2112.html
- https://www.samba.org/samba/security/CVE-2016-2112.html
Modified: 2024-11-21
CVE-2016-2113
Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof LDAPS and HTTPS servers and obtain sensitive information via a crafted certificate.
- http://badlock.org/
- http://badlock.org/
- FEDORA-2016-be53260726
- FEDORA-2016-be53260726
- FEDORA-2016-48b3761baa
- FEDORA-2016-48b3761baa
- FEDORA-2016-383fce04e2
- FEDORA-2016-383fce04e2
- SUSE-SU-2016:1022
- SUSE-SU-2016:1022
- SUSE-SU-2016:1023
- SUSE-SU-2016:1023
- SUSE-SU-2016:1024
- SUSE-SU-2016:1024
- openSUSE-SU-2016:1025
- openSUSE-SU-2016:1025
- SUSE-SU-2016:1028
- SUSE-SU-2016:1028
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1107
- openSUSE-SU-2016:1107
- RHSA-2016:0612
- RHSA-2016:0612
- RHSA-2016:0614
- RHSA-2016:0614
- RHSA-2016:0618
- RHSA-2016:0618
- RHSA-2016:0620
- RHSA-2016:0620
- DSA-3548
- DSA-3548
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 1035533
- 1035533
- SSA:2016-106-02
- SSA:2016-106-02
- USN-2950-1
- USN-2950-1
- USN-2950-2
- USN-2950-2
- USN-2950-3
- USN-2950-3
- USN-2950-4
- USN-2950-4
- USN-2950-5
- USN-2950-5
- https://bto.bluecoat.com/security-advisory/sa122
- https://bto.bluecoat.com/security-advisory/sa122
- GLSA-201612-47
- GLSA-201612-47
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/security/CVE-2016-2113.html
- https://www.samba.org/samba/security/CVE-2016-2113.html
Modified: 2024-11-21
CVE-2016-2114
The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "server signing = mandatory" setting, which allows man-in-the-middle attackers to spoof SMB servers by modifying the client-server data stream.
- http://badlock.org/
- http://badlock.org/
- FEDORA-2016-be53260726
- FEDORA-2016-be53260726
- FEDORA-2016-48b3761baa
- FEDORA-2016-48b3761baa
- FEDORA-2016-383fce04e2
- FEDORA-2016-383fce04e2
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1107
- openSUSE-SU-2016:1107
- RHSA-2016:0612
- RHSA-2016:0612
- RHSA-2016:0614
- RHSA-2016:0614
- RHSA-2016:0618
- RHSA-2016:0618
- RHSA-2016:0620
- RHSA-2016:0620
- DSA-3548
- DSA-3548
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 86011
- 86011
- 1035533
- 1035533
- SSA:2016-106-02
- SSA:2016-106-02
- USN-2950-1
- USN-2950-1
- USN-2950-2
- USN-2950-2
- USN-2950-3
- USN-2950-3
- USN-2950-4
- USN-2950-4
- USN-2950-5
- USN-2950-5
- https://bto.bluecoat.com/security-advisory/sa122
- https://bto.bluecoat.com/security-advisory/sa122
- GLSA-201612-47
- GLSA-201612-47
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/security/CVE-2016-2114.html
- https://www.samba.org/samba/security/CVE-2016-2114.html
Modified: 2024-11-21
CVE-2016-2115
Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying the client-server data stream.
- http://badlock.org/
- http://badlock.org/
- FEDORA-2016-be53260726
- FEDORA-2016-be53260726
- FEDORA-2016-48b3761baa
- FEDORA-2016-48b3761baa
- FEDORA-2016-383fce04e2
- FEDORA-2016-383fce04e2
- SUSE-SU-2016:1022
- SUSE-SU-2016:1022
- SUSE-SU-2016:1023
- SUSE-SU-2016:1023
- SUSE-SU-2016:1024
- SUSE-SU-2016:1024
- openSUSE-SU-2016:1025
- openSUSE-SU-2016:1025
- SUSE-SU-2016:1028
- SUSE-SU-2016:1028
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1107
- openSUSE-SU-2016:1107
- RHSA-2016:0611
- RHSA-2016:0611
- RHSA-2016:0612
- RHSA-2016:0612
- RHSA-2016:0613
- RHSA-2016:0613
- RHSA-2016:0614
- RHSA-2016:0614
- RHSA-2016:0618
- RHSA-2016:0618
- RHSA-2016:0619
- RHSA-2016:0619
- RHSA-2016:0620
- RHSA-2016:0620
- RHSA-2016:0624
- RHSA-2016:0624
- DSA-3548
- DSA-3548
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 1035533
- 1035533
- SSA:2016-106-02
- SSA:2016-106-02
- USN-2950-1
- USN-2950-1
- USN-2950-2
- USN-2950-2
- USN-2950-3
- USN-2950-3
- USN-2950-4
- USN-2950-4
- USN-2950-5
- USN-2950-5
- https://bto.bluecoat.com/security-advisory/sa122
- https://bto.bluecoat.com/security-advisory/sa122
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05087821
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05087821
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05082964
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05082964
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05162399
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05162399
- GLSA-201612-47
- GLSA-201612-47
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/security/CVE-2016-2115.html
- https://www.samba.org/samba/security/CVE-2016-2115.html
Modified: 2024-11-21
CVE-2016-2118
The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC connections, which allows man-in-the-middle attackers to perform protocol-downgrade attacks and impersonate users by modifying the client-server data stream, aka "BADLOCK."
- http://badlock.org/
- http://badlock.org/
- FEDORA-2016-be53260726
- FEDORA-2016-be53260726
- FEDORA-2016-48b3761baa
- FEDORA-2016-48b3761baa
- FEDORA-2016-383fce04e2
- FEDORA-2016-383fce04e2
- SUSE-SU-2016:1022
- SUSE-SU-2016:1022
- SUSE-SU-2016:1023
- SUSE-SU-2016:1023
- SUSE-SU-2016:1024
- SUSE-SU-2016:1024
- openSUSE-SU-2016:1025
- openSUSE-SU-2016:1025
- SUSE-SU-2016:1028
- SUSE-SU-2016:1028
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1064
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1106
- openSUSE-SU-2016:1107
- openSUSE-SU-2016:1107
- RHSA-2016:0611
- RHSA-2016:0611
- RHSA-2016:0612
- RHSA-2016:0612
- RHSA-2016:0613
- RHSA-2016:0613
- RHSA-2016:0614
- RHSA-2016:0614
- RHSA-2016:0618
- RHSA-2016:0618
- RHSA-2016:0619
- RHSA-2016:0619
- RHSA-2016:0620
- RHSA-2016:0620
- RHSA-2016:0621
- RHSA-2016:0621
- RHSA-2016:0623
- RHSA-2016:0623
- RHSA-2016:0624
- RHSA-2016:0624
- RHSA-2016:0625
- RHSA-2016:0625
- DSA-3548
- DSA-3548
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 86002
- 86002
- 1035533
- 1035533
- SSA:2016-106-02
- SSA:2016-106-02
- USN-2950-1
- USN-2950-1
- USN-2950-2
- USN-2950-2
- USN-2950-3
- USN-2950-3
- USN-2950-4
- USN-2950-4
- USN-2950-5
- USN-2950-5
- https://access.redhat.com/security/vulnerabilities/badlock
- https://access.redhat.com/security/vulnerabilities/badlock
- https://bto.bluecoat.com/security-advisory/sa122
- https://bto.bluecoat.com/security-advisory/sa122
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05162399
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05162399
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05166182
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05166182
- https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes
- https://help.ecostruxureit.com/display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes
- https://kb.netapp.com/support/s/article/ka51A0000008SXzQAM/smb-vulnerabilities-in-multiple-netapp-products
- https://kb.netapp.com/support/s/article/ka51A0000008SXzQAM/smb-vulnerabilities-in-multiple-netapp-products
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40196
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40196
- GLSA-201612-47
- GLSA-201612-47
- VU#813296
- VU#813296
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/history/samba-4.2.10.html
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/latest_news.html#4.4.2
- https://www.samba.org/samba/security/CVE-2016-2118.html
- https://www.samba.org/samba/security/CVE-2016-2118.html
Modified: 2024-11-21
CVE-2016-2119
libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a client-signing protection mechanism, and consequently spoof SMB2 and SMB3 servers, via the (1) SMB2_SESSION_FLAG_IS_GUEST or (2) SMB2_SESSION_FLAG_IS_NULL flag.
- openSUSE-SU-2016:1830
- openSUSE-SU-2016:1830
- RHSA-2016:1486
- RHSA-2016:1486
- RHSA-2016:1487
- RHSA-2016:1487
- RHSA-2016:1494
- RHSA-2016:1494
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 91700
- 91700
- 1036244
- 1036244
- GLSA-201805-07
- GLSA-201805-07
- https://www.samba.org/samba/security/CVE-2016-2119.html
- https://www.samba.org/samba/security/CVE-2016-2119.html
Modified: 2024-11-21
CVE-2016-2123
A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption. By default, all authenticated LDAP users can write to the dnsRecord attribute on new DNS objects. This makes the defect a remote privilege escalation.
Modified: 2024-11-21
CVE-2016-2125
It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to other services or domain users.
- RHSA-2017:0494
- RHSA-2017:0494
- RHSA-2017:0495
- RHSA-2017:0495
- RHSA-2017:0662
- RHSA-2017:0662
- RHSA-2017:0744
- RHSA-2017:0744
- 94988
- 94988
- 1037494
- 1037494
- RHSA-2017:1265
- RHSA-2017:1265
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-2125
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-2125
- https://www.samba.org/samba/security/CVE-2016-2125.html
- https://www.samba.org/samba/security/CVE-2016-2125.html
Modified: 2024-11-21
CVE-2016-2126
Samba version 4.0.0 up to 4.5.2 is vulnerable to privilege elevation due to incorrect handling of the PAC (Privilege Attribute Certificate) checksum. A remote, authenticated, attacker can cause the winbindd process to crash using a legitimate Kerberos ticket. A local service with access to the winbindd privileged pipe can cause winbindd to cache elevated access permissions.
- RHSA-2017:0494
- RHSA-2017:0494
- RHSA-2017:0495
- RHSA-2017:0495
- RHSA-2017:0662
- RHSA-2017:0662
- RHSA-2017:0744
- RHSA-2017:0744
- 94994
- 94994
- 1037495
- 1037495
- RHSA-2017:1265
- RHSA-2017:1265
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43730
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43730
- https://www.samba.org/samba/security/CVE-2016-2126.html
- https://www.samba.org/samba/security/CVE-2016-2126.html
Modified: 2024-11-21
CVE-2017-11103
Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.
- DSA-3912
- DSA-3912
- http://www.h5l.org/advisories.html?show=2017-07-11
- http://www.h5l.org/advisories.html?show=2017-07-11
- 99551
- 99551
- 1038876
- 1038876
- 1039427
- 1039427
- https://github.com/heimdal/heimdal/releases/tag/heimdal-7.4.0
- https://github.com/heimdal/heimdal/releases/tag/heimdal-7.4.0
- https://support.apple.com/HT208112
- https://support.apple.com/HT208112
- https://support.apple.com/HT208144
- https://support.apple.com/HT208144
- https://support.apple.com/HT208221
- https://support.apple.com/HT208221
- FreeBSD-SA-17:05
- FreeBSD-SA-17:05
- https://www.orpheus-lyre.info/
- https://www.orpheus-lyre.info/
- https://www.samba.org/samba/security/CVE-2017-11103.html
- https://www.samba.org/samba/security/CVE-2017-11103.html
Modified: 2024-11-21
CVE-2017-12150
It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-the-middle attack and retrieve information in plain-text.
- 100918
- 100918
- 1039401
- 1039401
- RHSA-2017:2789
- RHSA-2017:2789
- RHSA-2017:2790
- RHSA-2017:2790
- RHSA-2017:2791
- RHSA-2017:2791
- RHSA-2017:2858
- RHSA-2017:2858
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12150
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12150
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03775en_us
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03775en_us
- https://security.netapp.com/advisory/ntap-20170921-0001/
- https://security.netapp.com/advisory/ntap-20170921-0001/
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- DSA-3983
- DSA-3983
- https://www.samba.org/samba/security/CVE-2017-12150.html
- https://www.samba.org/samba/security/CVE-2017-12150.html
Modified: 2024-11-21
CVE-2017-12151
A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack.
- 100917
- 100917
- 1039401
- 1039401
- RHSA-2017:2790
- RHSA-2017:2790
- RHSA-2017:2858
- RHSA-2017:2858
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12151
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12151
- https://security.netapp.com/advisory/ntap-20170921-0001/
- https://security.netapp.com/advisory/ntap-20170921-0001/
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- DSA-3983
- DSA-3983
- https://www.samba.org/samba/security/CVE-2017-12151.html
- https://www.samba.org/samba/security/CVE-2017-12151.html
Modified: 2024-11-21
CVE-2017-12163
An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker.
- 100925
- 100925
- 1039401
- 1039401
- RHSA-2017:2789
- RHSA-2017:2789
- RHSA-2017:2790
- RHSA-2017:2790
- RHSA-2017:2791
- RHSA-2017:2791
- RHSA-2017:2858
- RHSA-2017:2858
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12163
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12163
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03775en_us
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03775en_us
- https://security.netapp.com/advisory/ntap-20170921-0001/
- https://security.netapp.com/advisory/ntap-20170921-0001/
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- DSA-3983
- DSA-3983
- https://www.samba.org/samba/security/CVE-2017-12163.html
- https://www.samba.org/samba/security/CVE-2017-12163.html
- https://www.synology.com/support/security/Synology_SA_17_57_Samba
- https://www.synology.com/support/security/Synology_SA_17_57_Samba
Modified: 2024-11-21
CVE-2017-14746
Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.
- 101907
- 101907
- 1039856
- 1039856
- USN-3486-1
- USN-3486-1
- RHSA-2017:3260
- RHSA-2017:3260
- RHSA-2017:3261
- RHSA-2017:3261
- RHSA-2017:3278
- RHSA-2017:3278
- GLSA-201805-07
- GLSA-201805-07
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- DSA-4043
- DSA-4043
- https://www.samba.org/samba/security/CVE-2017-14746.html
- https://www.samba.org/samba/security/CVE-2017-14746.html
- https://www.synology.com/support/security/Synology_SA_17_72_Samba
- https://www.synology.com/support/security/Synology_SA_17_72_Samba
Modified: 2024-11-21
CVE-2017-15275
Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.
- 101908
- 101908
- 1039855
- 1039855
- USN-3486-1
- USN-3486-1
- USN-3486-2
- USN-3486-2
- RHSA-2017:3260
- RHSA-2017:3260
- RHSA-2017:3261
- RHSA-2017:3261
- RHSA-2017:3278
- RHSA-2017:3278
- [debian-lts-announce] 20171121 [SECURITY] [DLA 1183-1] samba security update
- [debian-lts-announce] 20171121 [SECURITY] [DLA 1183-1] samba security update
- GLSA-201805-07
- GLSA-201805-07
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- DSA-4043
- DSA-4043
- https://www.samba.org/samba/security/CVE-2017-15275.html
- https://www.samba.org/samba/security/CVE-2017-15275.html
- https://www.synology.com/support/security/Synology_SA_17_72_Samba
- https://www.synology.com/support/security/Synology_SA_17_72_Samba
Modified: 2024-11-21
CVE-2017-2619
Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access to areas of the server file system not exported under the share definition.
- 97033
- 97033
- 1038117
- 1038117
- RHSA-2017:1265
- RHSA-2017:1265
- RHSA-2017:2338
- RHSA-2017:2338
- RHSA-2017:2778
- RHSA-2017:2778
- RHSA-2017:2789
- RHSA-2017:2789
- https://bugzilla.redhat.com/show_bug.cgi?id=1429472
- https://bugzilla.redhat.com/show_bug.cgi?id=1429472
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03755en_us
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03755en_us
- DSA-3816
- DSA-3816
- 41740
- 41740
- https://www.samba.org/samba/security/CVE-2017-2619.html
- https://www.samba.org/samba/security/CVE-2017-2619.html
Modified: 2025-02-07
CVE-2017-7494
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.
- DSA-3860
- DSA-3860
- 98636
- 98636
- 1038552
- 1038552
- RHSA-2017:1270
- RHSA-2017:1270
- RHSA-2017:1271
- RHSA-2017:1271
- RHSA-2017:1272
- RHSA-2017:1272
- RHSA-2017:1273
- RHSA-2017:1273
- RHSA-2017:1390
- RHSA-2017:1390
- https://download.schneider-electric.com/files?p_enDocType=Technical+leaflet&p_File_Name=SEVD-2018-095-01+Security+Notification+Umotion+V1.1.pdf&p_Doc_Ref=SEVD-2018-095-01
- https://download.schneider-electric.com/files?p_enDocType=Technical+leaflet&p_File_Name=SEVD-2018-095-01+Security+Notification+Umotion+V1.1.pdf&p_Doc_Ref=SEVD-2018-095-01
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03755en_us
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03755en_us
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03759en_us
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03759en_us
- GLSA-201805-07
- GLSA-201805-07
- https://security.netapp.com/advisory/ntap-20170524-0001/
- https://security.netapp.com/advisory/ntap-20170524-0001/
- 42060
- 42060
- 42084
- 42084
- https://www.samba.org/samba/security/CVE-2017-7494.html
- https://www.samba.org/samba/security/CVE-2017-7494.html
Modified: 2024-11-21
CVE-2018-1050
All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls could cause the print spooler service to crash.
- 103387
- 103387
- 1040493
- 1040493
- RHSA-2018:1860
- RHSA-2018:1860
- RHSA-2018:1883
- RHSA-2018:1883
- RHSA-2018:2612
- RHSA-2018:2612
- RHSA-2018:2613
- RHSA-2018:2613
- RHSA-2018:3056
- RHSA-2018:3056
- https://bugzilla.redhat.com/show_bug.cgi?id=1538771
- https://bugzilla.redhat.com/show_bug.cgi?id=1538771
- https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
- https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
- [debian-lts-announce] 20180327 [SECURITY] [DLA 1320-1] samba security update
- [debian-lts-announce] 20180327 [SECURITY] [DLA 1320-1] samba security update
- [debian-lts-announce] 20190409 [SECURITY] [DLA 1754-1] samba security update
- [debian-lts-announce] 20190409 [SECURITY] [DLA 1754-1] samba security update
- GLSA-201805-07
- GLSA-201805-07
- https://security.netapp.com/advisory/ntap-20180313-0001/
- https://security.netapp.com/advisory/ntap-20180313-0001/
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03834en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03834en_us
- USN-3595-1
- USN-3595-1
- USN-3595-2
- USN-3595-2
- DSA-4135
- DSA-4135
- https://www.samba.org/samba/security/CVE-2018-1050.html
- https://www.samba.org/samba/security/CVE-2018-1050.html
Modified: 2024-11-21
CVE-2018-1057
On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users and privileged service accounts (eg Domain Controllers).
- 103382
- 103382
- 1040494
- 1040494
- https://bugzilla.redhat.com/show_bug.cgi?id=1553553
- https://bugzilla.redhat.com/show_bug.cgi?id=1553553
- [debian-lts-announce] 20190409 [SECURITY] [DLA 1754-1] samba security update
- [debian-lts-announce] 20190409 [SECURITY] [DLA 1754-1] samba security update
- GLSA-201805-07
- GLSA-201805-07
- https://security.netapp.com/advisory/ntap-20180313-0001/
- https://security.netapp.com/advisory/ntap-20180313-0001/
- USN-3595-1
- USN-3595-1
- DSA-4135
- DSA-4135
- https://www.samba.org/samba/security/CVE-2018-1057.html
- https://www.samba.org/samba/security/CVE-2018-1057.html
- https://www.synology.com/support/security/Synology_SA_18_08
- https://www.synology.com/support/security/Synology_SA_18_08
Closed bugs
[PATCH] исправление работы --without docs
samba ругается на rlimit_max
Closed vulnerabilities
BDU:2016-01705
Уязвимость файловой системы Samba, позволяющая нарушителю подменить протоколы SMB2 и SMB3 серверов
BDU:2017-01262
Уязвимость сетевой файловой системы Samba, позволяющая выполнить произвольный код
BDU:2018-00367
Уязвимость пакета программ сетевого взаимодействия Samba, связанная с отсутствием проверки входных данных, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2018-00368
Уязвимость сервера LDAP пакета программ сетевого взаимодействия Samba, позволяющая нарушителю изменять пароли других пользователей
BDU:2019-00223
Уязвимость пакета программ для сетевого взаимодействия Samba, связанная с отсутствием подписи SMB-трафика, позволяющая нарушителю реализовать атаку «человек посередине»
BDU:2019-00224
Уязвимость пакета программ для сетевого взаимодействия Samba, связанная с отсутствием требования подписи и шифрования SMB-трафика при использовании перенаправлений DFS, позволяющая нарушителю реализовать атаку «человек посередине»
BDU:2021-01289
Уязвимость парсера ndr_pull_dnsp_name пакета программ сетевого взаимодействия Samba, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01421
Уязвимость пакета программ сетевого взаимодействия Samba, связанная с одновременным выполнением с использованием общего ресурса с неправильной синхронизацией, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01422
Уязвимость реализации протокола SMB1 пакета программ сетевого взаимодействия Samba, связанная с использованием области памяти после её освобождения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01424
Уязвимость функции _krb5_extract_ticket() пакета программ сетевого взаимодействия Samba, связанная с недостатком механизма проверки подлинности данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01425
Уязвимость реализации протокола Kerberos пакета программ сетевого взаимодействия Samba, связанная с недостатком механизма контроля привилегий и средств управления доступом, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-01433
Уязвимость реализации протокола SMB1 пакета программ сетевого взаимодействия Samba, позволяющая нарушителю получить доступ к конфиденциальным данным и нарушить их целостность
BDU:2021-01435
Уязвимость пакета программ сетевого взаимодействия Samba, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным
Modified: 2024-11-21
CVE-2016-2119
libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a client-signing protection mechanism, and consequently spoof SMB2 and SMB3 servers, via the (1) SMB2_SESSION_FLAG_IS_GUEST or (2) SMB2_SESSION_FLAG_IS_NULL flag.
- openSUSE-SU-2016:1830
- openSUSE-SU-2016:1830
- RHSA-2016:1486
- RHSA-2016:1486
- RHSA-2016:1487
- RHSA-2016:1487
- RHSA-2016:1494
- RHSA-2016:1494
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- 91700
- 91700
- 1036244
- 1036244
- GLSA-201805-07
- GLSA-201805-07
- https://www.samba.org/samba/security/CVE-2016-2119.html
- https://www.samba.org/samba/security/CVE-2016-2119.html
Modified: 2024-11-21
CVE-2016-2123
A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption. By default, all authenticated LDAP users can write to the dnsRecord attribute on new DNS objects. This makes the defect a remote privilege escalation.
Modified: 2024-11-21
CVE-2016-2125
It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to other services or domain users.
- RHSA-2017:0494
- RHSA-2017:0494
- RHSA-2017:0495
- RHSA-2017:0495
- RHSA-2017:0662
- RHSA-2017:0662
- RHSA-2017:0744
- RHSA-2017:0744
- 94988
- 94988
- 1037494
- 1037494
- RHSA-2017:1265
- RHSA-2017:1265
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-2125
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-2125
- https://www.samba.org/samba/security/CVE-2016-2125.html
- https://www.samba.org/samba/security/CVE-2016-2125.html
Modified: 2024-11-21
CVE-2016-2126
Samba version 4.0.0 up to 4.5.2 is vulnerable to privilege elevation due to incorrect handling of the PAC (Privilege Attribute Certificate) checksum. A remote, authenticated, attacker can cause the winbindd process to crash using a legitimate Kerberos ticket. A local service with access to the winbindd privileged pipe can cause winbindd to cache elevated access permissions.
- RHSA-2017:0494
- RHSA-2017:0494
- RHSA-2017:0495
- RHSA-2017:0495
- RHSA-2017:0662
- RHSA-2017:0662
- RHSA-2017:0744
- RHSA-2017:0744
- 94994
- 94994
- 1037495
- 1037495
- RHSA-2017:1265
- RHSA-2017:1265
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43730
- https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43730
- https://www.samba.org/samba/security/CVE-2016-2126.html
- https://www.samba.org/samba/security/CVE-2016-2126.html
Modified: 2024-11-21
CVE-2017-11103
Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.
- DSA-3912
- DSA-3912
- http://www.h5l.org/advisories.html?show=2017-07-11
- http://www.h5l.org/advisories.html?show=2017-07-11
- 99551
- 99551
- 1038876
- 1038876
- 1039427
- 1039427
- https://github.com/heimdal/heimdal/releases/tag/heimdal-7.4.0
- https://github.com/heimdal/heimdal/releases/tag/heimdal-7.4.0
- https://support.apple.com/HT208112
- https://support.apple.com/HT208112
- https://support.apple.com/HT208144
- https://support.apple.com/HT208144
- https://support.apple.com/HT208221
- https://support.apple.com/HT208221
- FreeBSD-SA-17:05
- FreeBSD-SA-17:05
- https://www.orpheus-lyre.info/
- https://www.orpheus-lyre.info/
- https://www.samba.org/samba/security/CVE-2017-11103.html
- https://www.samba.org/samba/security/CVE-2017-11103.html
Modified: 2024-11-21
CVE-2017-12150
It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-the-middle attack and retrieve information in plain-text.
- 100918
- 100918
- 1039401
- 1039401
- RHSA-2017:2789
- RHSA-2017:2789
- RHSA-2017:2790
- RHSA-2017:2790
- RHSA-2017:2791
- RHSA-2017:2791
- RHSA-2017:2858
- RHSA-2017:2858
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12150
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12150
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03775en_us
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03775en_us
- https://security.netapp.com/advisory/ntap-20170921-0001/
- https://security.netapp.com/advisory/ntap-20170921-0001/
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- DSA-3983
- DSA-3983
- https://www.samba.org/samba/security/CVE-2017-12150.html
- https://www.samba.org/samba/security/CVE-2017-12150.html
Modified: 2024-11-21
CVE-2017-12151
A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack.
- 100917
- 100917
- 1039401
- 1039401
- RHSA-2017:2790
- RHSA-2017:2790
- RHSA-2017:2858
- RHSA-2017:2858
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12151
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12151
- https://security.netapp.com/advisory/ntap-20170921-0001/
- https://security.netapp.com/advisory/ntap-20170921-0001/
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- DSA-3983
- DSA-3983
- https://www.samba.org/samba/security/CVE-2017-12151.html
- https://www.samba.org/samba/security/CVE-2017-12151.html
Modified: 2024-11-21
CVE-2017-12163
An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker.
- 100925
- 100925
- 1039401
- 1039401
- RHSA-2017:2789
- RHSA-2017:2789
- RHSA-2017:2790
- RHSA-2017:2790
- RHSA-2017:2791
- RHSA-2017:2791
- RHSA-2017:2858
- RHSA-2017:2858
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12163
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12163
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03775en_us
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03775en_us
- https://security.netapp.com/advisory/ntap-20170921-0001/
- https://security.netapp.com/advisory/ntap-20170921-0001/
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- DSA-3983
- DSA-3983
- https://www.samba.org/samba/security/CVE-2017-12163.html
- https://www.samba.org/samba/security/CVE-2017-12163.html
- https://www.synology.com/support/security/Synology_SA_17_57_Samba
- https://www.synology.com/support/security/Synology_SA_17_57_Samba
Modified: 2024-11-21
CVE-2017-14746
Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.
- 101907
- 101907
- 1039856
- 1039856
- USN-3486-1
- USN-3486-1
- RHSA-2017:3260
- RHSA-2017:3260
- RHSA-2017:3261
- RHSA-2017:3261
- RHSA-2017:3278
- RHSA-2017:3278
- GLSA-201805-07
- GLSA-201805-07
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- DSA-4043
- DSA-4043
- https://www.samba.org/samba/security/CVE-2017-14746.html
- https://www.samba.org/samba/security/CVE-2017-14746.html
- https://www.synology.com/support/security/Synology_SA_17_72_Samba
- https://www.synology.com/support/security/Synology_SA_17_72_Samba
Modified: 2024-11-21
CVE-2017-15275
Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.
- 101908
- 101908
- 1039855
- 1039855
- USN-3486-1
- USN-3486-1
- USN-3486-2
- USN-3486-2
- RHSA-2017:3260
- RHSA-2017:3260
- RHSA-2017:3261
- RHSA-2017:3261
- RHSA-2017:3278
- RHSA-2017:3278
- [debian-lts-announce] 20171121 [SECURITY] [DLA 1183-1] samba security update
- [debian-lts-announce] 20171121 [SECURITY] [DLA 1183-1] samba security update
- GLSA-201805-07
- GLSA-201805-07
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03817en_us
- DSA-4043
- DSA-4043
- https://www.samba.org/samba/security/CVE-2017-15275.html
- https://www.samba.org/samba/security/CVE-2017-15275.html
- https://www.synology.com/support/security/Synology_SA_17_72_Samba
- https://www.synology.com/support/security/Synology_SA_17_72_Samba
Modified: 2024-11-21
CVE-2017-2619
Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access to areas of the server file system not exported under the share definition.
- 97033
- 97033
- 1038117
- 1038117
- RHSA-2017:1265
- RHSA-2017:1265
- RHSA-2017:2338
- RHSA-2017:2338
- RHSA-2017:2778
- RHSA-2017:2778
- RHSA-2017:2789
- RHSA-2017:2789
- https://bugzilla.redhat.com/show_bug.cgi?id=1429472
- https://bugzilla.redhat.com/show_bug.cgi?id=1429472
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03755en_us
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03755en_us
- DSA-3816
- DSA-3816
- 41740
- 41740
- https://www.samba.org/samba/security/CVE-2017-2619.html
- https://www.samba.org/samba/security/CVE-2017-2619.html
Modified: 2025-02-07
CVE-2017-7494
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.
- DSA-3860
- DSA-3860
- 98636
- 98636
- 1038552
- 1038552
- RHSA-2017:1270
- RHSA-2017:1270
- RHSA-2017:1271
- RHSA-2017:1271
- RHSA-2017:1272
- RHSA-2017:1272
- RHSA-2017:1273
- RHSA-2017:1273
- RHSA-2017:1390
- RHSA-2017:1390
- https://download.schneider-electric.com/files?p_enDocType=Technical+leaflet&p_File_Name=SEVD-2018-095-01+Security+Notification+Umotion+V1.1.pdf&p_Doc_Ref=SEVD-2018-095-01
- https://download.schneider-electric.com/files?p_enDocType=Technical+leaflet&p_File_Name=SEVD-2018-095-01+Security+Notification+Umotion+V1.1.pdf&p_Doc_Ref=SEVD-2018-095-01
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03755en_us
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03755en_us
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03759en_us
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03759en_us
- GLSA-201805-07
- GLSA-201805-07
- https://security.netapp.com/advisory/ntap-20170524-0001/
- https://security.netapp.com/advisory/ntap-20170524-0001/
- 42060
- 42060
- 42084
- 42084
- https://www.samba.org/samba/security/CVE-2017-7494.html
- https://www.samba.org/samba/security/CVE-2017-7494.html
Modified: 2024-11-21
CVE-2018-1050
All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls could cause the print spooler service to crash.
- 103387
- 103387
- 1040493
- 1040493
- RHSA-2018:1860
- RHSA-2018:1860
- RHSA-2018:1883
- RHSA-2018:1883
- RHSA-2018:2612
- RHSA-2018:2612
- RHSA-2018:2613
- RHSA-2018:2613
- RHSA-2018:3056
- RHSA-2018:3056
- https://bugzilla.redhat.com/show_bug.cgi?id=1538771
- https://bugzilla.redhat.com/show_bug.cgi?id=1538771
- https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
- https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0
- [debian-lts-announce] 20180327 [SECURITY] [DLA 1320-1] samba security update
- [debian-lts-announce] 20180327 [SECURITY] [DLA 1320-1] samba security update
- [debian-lts-announce] 20190409 [SECURITY] [DLA 1754-1] samba security update
- [debian-lts-announce] 20190409 [SECURITY] [DLA 1754-1] samba security update
- GLSA-201805-07
- GLSA-201805-07
- https://security.netapp.com/advisory/ntap-20180313-0001/
- https://security.netapp.com/advisory/ntap-20180313-0001/
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03834en_us
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbns03834en_us
- USN-3595-1
- USN-3595-1
- USN-3595-2
- USN-3595-2
- DSA-4135
- DSA-4135
- https://www.samba.org/samba/security/CVE-2018-1050.html
- https://www.samba.org/samba/security/CVE-2018-1050.html
Modified: 2024-11-21
CVE-2018-1057
On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users and privileged service accounts (eg Domain Controllers).
- 103382
- 103382
- 1040494
- 1040494
- https://bugzilla.redhat.com/show_bug.cgi?id=1553553
- https://bugzilla.redhat.com/show_bug.cgi?id=1553553
- [debian-lts-announce] 20190409 [SECURITY] [DLA 1754-1] samba security update
- [debian-lts-announce] 20190409 [SECURITY] [DLA 1754-1] samba security update
- GLSA-201805-07
- GLSA-201805-07
- https://security.netapp.com/advisory/ntap-20180313-0001/
- https://security.netapp.com/advisory/ntap-20180313-0001/
- USN-3595-1
- USN-3595-1
- DSA-4135
- DSA-4135
- https://www.samba.org/samba/security/CVE-2018-1057.html
- https://www.samba.org/samba/security/CVE-2018-1057.html
- https://www.synology.com/support/security/Synology_SA_18_08
- https://www.synology.com/support/security/Synology_SA_18_08
Closed bugs
[PATCH] исправление работы --without docs
samba ругается на rlimit_max
Closed vulnerabilities
BDU:2015-06304
Уязвимости операционной системы Red Hat Enterprise Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
BDU:2015-06305
Уязвимости операционной системы Red Hat Enterprise Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
BDU:2015-09087
Уязвимости операционной системы CentOS, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
BDU:2015-09088
Уязвимости операционной системы CentOS, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
BDU:2015-09726
Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
BDU:2015-09763
Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность и целостность защищаемой информации
BDU:2016-01656
Уязвимость библиотеки cURL, позволяющая нарушителю пройти аутентификацию от имени другого пользователя
BDU:2018-00107
Уязвимость функции sendto программного средства для взаимодействия с серверами curl, позволяющая нарушителю вызвать отказ в обслуживании или осуществить перенаправление трафика
BDU:2018-00108
Уязвимость синтаксического анализатора программного средства для взаимодействия с серверами curl, позволяющая нарушителю выполнить чтение за границами буфера в памяти
Modified: 2024-11-21
CVE-2013-4545
cURL and libcurl 7.18.0 through 7.32.0, when built with OpenSSL, disables the certificate CN and SAN name field verification (CURLOPT_SSL_VERIFYHOST) when the digital signature verification (CURLOPT_SSL_VERIFYPEER) is disabled, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
- http://curl.haxx.se/docs/adv_20131115.html
- http://curl.haxx.se/docs/adv_20131115.html
- openSUSE-SU-2013:1859
- openSUSE-SU-2013:1859
- openSUSE-SU-2013:1865
- openSUSE-SU-2013:1865
- DSA-2798
- DSA-2798
- http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html
- http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
- USN-2048-1
- USN-2048-1
- HPSBMU03112
- HPSBMU03112
Modified: 2024-11-21
CVE-2013-6422
The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
Modified: 2024-11-21
CVE-2014-0015
cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.
- APPLE-SA-2014-06-30-2
- APPLE-SA-2014-06-30-2
- http://curl.haxx.se/docs/adv_20140129.html
- http://curl.haxx.se/docs/adv_20140129.html
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- FEDORA-2014-1876
- FEDORA-2014-1876
- FEDORA-2014-1864
- FEDORA-2014-1864
- openSUSE-SU-2014:0274
- openSUSE-SU-2014:0274
- 20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities
- 20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities
- 56728
- 56728
- 56731
- 56731
- 56734
- 56734
- 56912
- 56912
- 59458
- 59458
- 59475
- 59475
- http://support.apple.com/kb/HT6296
- http://support.apple.com/kb/HT6296
- DSA-2849
- DSA-2849
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
- 20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities
- 20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities
- 65270
- 65270
- 1029710
- 1029710
- SSA:2014-044-01
- SSA:2014-044-01
- USN-2097-1
- USN-2097-1
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095862
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095862
Modified: 2024-11-21
CVE-2014-0138
The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.
- http://curl.haxx.se/docs/adv_20140326A.html
- http://curl.haxx.se/docs/adv_20140326A.html
- openSUSE-SU-2014:0530
- openSUSE-SU-2014:0530
- 20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities
- 20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities
- 57836
- 57836
- 57966
- 57966
- 57968
- 57968
- 58615
- 58615
- 59458
- 59458
- DSA-2902
- DSA-2902
- http://www.getchef.com/blog/2014/04/09/chef-server-11-0-12-release/
- http://www.getchef.com/blog/2014/04/09/chef-server-11-0-12-release/
- http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/
- http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/
- http://www.getchef.com/blog/2014/04/09/enterprise-chef-1-4-9-release/
- http://www.getchef.com/blog/2014/04/09/enterprise-chef-1-4-9-release/
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
- 20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities
- 20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities
- USN-2167-1
- USN-2167-1
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html
- http://www-01.ibm.com/support/docview.wss?uid=swg21675820
- http://www-01.ibm.com/support/docview.wss?uid=swg21675820
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095862
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095862
Modified: 2024-11-21
CVE-2014-0139
cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
- http://advisories.mageia.org/MGASA-2015-0165.html
- http://advisories.mageia.org/MGASA-2015-0165.html
- http://curl.haxx.se/docs/adv_20140326B.html
- http://curl.haxx.se/docs/adv_20140326B.html
- openSUSE-SU-2014:0530
- openSUSE-SU-2014:0530
- 57836
- 57836
- 57966
- 57966
- 57968
- 57968
- 58615
- 58615
- 59458
- 59458
- DSA-2902
- DSA-2902
- http://www.getchef.com/blog/2014/04/09/chef-server-11-0-12-release/
- http://www.getchef.com/blog/2014/04/09/chef-server-11-0-12-release/
- http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/
- http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/
- http://www.getchef.com/blog/2014/04/09/enterprise-chef-1-4-9-release/
- http://www.getchef.com/blog/2014/04/09/enterprise-chef-1-4-9-release/
- MDVSA-2015:213
- MDVSA-2015:213
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
- USN-2167-1
- USN-2167-1
- http://www-01.ibm.com/support/docview.wss?uid=swg21675820
- http://www-01.ibm.com/support/docview.wss?uid=swg21675820
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095862
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095862
Modified: 2024-11-21
CVE-2014-3613
cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1.
- http://curl.haxx.se/docs/adv_20140910A.html
- http://curl.haxx.se/docs/adv_20140910A.html
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- APPLE-SA-2015-08-13-2
- APPLE-SA-2015-08-13-2
- openSUSE-SU-2014:1139
- openSUSE-SU-2014:1139
- RHSA-2015:1254
- RHSA-2015:1254
- DSA-3022
- DSA-3022
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- 69748
- 69748
- https://support.apple.com/kb/HT205031
- https://support.apple.com/kb/HT205031
Modified: 2024-11-21
CVE-2014-3620
cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.
- http://curl.haxx.se/docs/adv_20140910B.html
- http://curl.haxx.se/docs/adv_20140910B.html
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- APPLE-SA-2015-08-13-2
- APPLE-SA-2015-08-13-2
- openSUSE-SU-2014:1139
- openSUSE-SU-2014:1139
- DSA-3022
- DSA-3022
- [oss-security] 20220511 [SECURITY ADVISORY] curl: cookie for trailing dot TLD
- [oss-security] 20220511 [SECURITY ADVISORY] curl: cookie for trailing dot TLD
- 69742
- 69742
- https://support.apple.com/kb/HT205031
- https://support.apple.com/kb/HT205031
Modified: 2024-11-21
CVE-2014-3707
The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to read sensitive memory information.
- http://curl.haxx.se/docs/adv_20141105.html
- http://curl.haxx.se/docs/adv_20141105.html
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- APPLE-SA-2015-08-13-2
- APPLE-SA-2015-08-13-2
- openSUSE-SU-2015:0248
- openSUSE-SU-2015:0248
- RHSA-2015:1254
- RHSA-2015:1254
- DSA-3069
- DSA-3069
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- 70988
- 70988
- USN-2399-1
- USN-2399-1
- https://support.apple.com/kb/HT205031
- https://support.apple.com/kb/HT205031
Modified: 2024-11-21
CVE-2014-8150
CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a URL.
- http://advisories.mageia.org/MGASA-2015-0020.html
- http://advisories.mageia.org/MGASA-2015-0020.html
- http://curl.haxx.se/docs/adv_20150108B.html
- http://curl.haxx.se/docs/adv_20150108B.html
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- APPLE-SA-2015-08-13-2
- APPLE-SA-2015-08-13-2
- FEDORA-2015-0418
- FEDORA-2015-0418
- FEDORA-2015-0415
- FEDORA-2015-0415
- FEDORA-2015-6864
- FEDORA-2015-6864
- FEDORA-2015-6853
- FEDORA-2015-6853
- openSUSE-SU-2015:0248
- openSUSE-SU-2015:0248
- RHSA-2015:1254
- RHSA-2015:1254
- 61925
- 61925
- 62075
- 62075
- 62361
- 62361
- DSA-3122
- DSA-3122
- MDVSA-2015:021
- MDVSA-2015:021
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
- http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- 71964
- 71964
- 1032768
- 1032768
- USN-2474-1
- USN-2474-1
- https://kc.mcafee.com/corporate/index?page=content&id=SB10131
- https://kc.mcafee.com/corporate/index?page=content&id=SB10131
- GLSA-201701-47
- GLSA-201701-47
- https://support.apple.com/kb/HT205031
- https://support.apple.com/kb/HT205031
Modified: 2024-11-21
CVE-2014-8151
The darwinssl_connect_step1 function in lib/vtls/curl_darwinssl.c in libcurl 7.31.0 through 7.39.0, when using the DarwinSSL (aka SecureTransport) back-end for TLS, does not check if a cached TLS session validated the certificate when reusing the session, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
- http://curl.haxx.se/docs/adv_20150108A.html
- http://curl.haxx.se/docs/adv_20150108A.html
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- APPLE-SA-2015-08-13-2
- APPLE-SA-2015-08-13-2
- 61925
- 61925
- GLSA-201701-47
- GLSA-201701-47
- https://support.apple.com/kb/HT205031
- https://support.apple.com/kb/HT205031
Modified: 2024-11-21
CVE-2015-3143
cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015.
- http://advisories.mageia.org/MGASA-2015-0179.html
- http://advisories.mageia.org/MGASA-2015-0179.html
- http://curl.haxx.se/docs/adv_20150422A.html
- http://curl.haxx.se/docs/adv_20150422A.html
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- APPLE-SA-2015-08-13-2
- APPLE-SA-2015-08-13-2
- FEDORA-2015-6695
- FEDORA-2015-6695
- FEDORA-2015-6712
- FEDORA-2015-6712
- FEDORA-2015-6864
- FEDORA-2015-6864
- FEDORA-2015-6728
- FEDORA-2015-6728
- FEDORA-2015-6853
- FEDORA-2015-6853
- openSUSE-SU-2015:0799
- openSUSE-SU-2015:0799
- HPSBHF03544
- HPSBHF03544
- RHSA-2015:1254
- RHSA-2015:1254
- DSA-3232
- DSA-3232
- MDVSA-2015:219
- MDVSA-2015:219
- MDVSA-2015:220
- MDVSA-2015:220
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- 74299
- 74299
- 1032232
- 1032232
- USN-2591-1
- USN-2591-1
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05045763
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05045763
- GLSA-201509-02
- GLSA-201509-02
- https://support.apple.com/kb/HT205031
- https://support.apple.com/kb/HT205031
Modified: 2024-11-21
CVE-2015-3144
The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."
- http://curl.haxx.se/docs/adv_20150422D.html
- http://curl.haxx.se/docs/adv_20150422D.html
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- APPLE-SA-2015-08-13-2
- APPLE-SA-2015-08-13-2
- FEDORA-2015-6695
- FEDORA-2015-6695
- FEDORA-2015-6864
- FEDORA-2015-6864
- FEDORA-2015-6728
- FEDORA-2015-6728
- FEDORA-2015-6853
- FEDORA-2015-6853
- openSUSE-SU-2015:0799
- openSUSE-SU-2015:0799
- DSA-3232
- DSA-3232
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
- 74300
- 74300
- 1032232
- 1032232
- USN-2591-1
- USN-2591-1
- GLSA-201509-02
- GLSA-201509-02
- https://support.apple.com/kb/HT205031
- https://support.apple.com/kb/HT205031
Modified: 2024-11-21
CVE-2015-3145
The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly have other unspecified impact via a cookie path containing only a double-quote character.
- http://advisories.mageia.org/MGASA-2015-0179.html
- http://advisories.mageia.org/MGASA-2015-0179.html
- http://curl.haxx.se/docs/adv_20150422C.html
- http://curl.haxx.se/docs/adv_20150422C.html
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- APPLE-SA-2015-08-13-2
- APPLE-SA-2015-08-13-2
- FEDORA-2015-6695
- FEDORA-2015-6695
- FEDORA-2015-6712
- FEDORA-2015-6712
- FEDORA-2015-6864
- FEDORA-2015-6864
- FEDORA-2015-6728
- FEDORA-2015-6728
- FEDORA-2015-6853
- FEDORA-2015-6853
- openSUSE-SU-2015:0799
- openSUSE-SU-2015:0799
- DSA-3232
- DSA-3232
- MDVSA-2015:219
- MDVSA-2015:219
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
- 74303
- 74303
- 1032232
- 1032232
- USN-2591-1
- USN-2591-1
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05045763
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05045763
- GLSA-201509-02
- GLSA-201509-02
- https://support.apple.com/kb/HT205031
- https://support.apple.com/kb/HT205031
Modified: 2024-11-21
CVE-2015-3148
cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.
- http://advisories.mageia.org/MGASA-2015-0179.html
- http://advisories.mageia.org/MGASA-2015-0179.html
- http://curl.haxx.se/docs/adv_20150422B.html
- http://curl.haxx.se/docs/adv_20150422B.html
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- APPLE-SA-2015-08-13-2
- APPLE-SA-2015-08-13-2
- FEDORA-2015-6695
- FEDORA-2015-6695
- FEDORA-2015-6712
- FEDORA-2015-6712
- FEDORA-2015-6864
- FEDORA-2015-6864
- FEDORA-2015-6728
- FEDORA-2015-6728
- FEDORA-2015-6853
- FEDORA-2015-6853
- openSUSE-SU-2015:0799
- openSUSE-SU-2015:0799
- HPSBHF03544
- HPSBHF03544
- RHSA-2015:1254
- RHSA-2015:1254
- DSA-3232
- DSA-3232
- MDVSA-2015:219
- MDVSA-2015:219
- MDVSA-2015:220
- MDVSA-2015:220
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- 74301
- 74301
- 1032232
- 1032232
- USN-2591-1
- USN-2591-1
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05045763
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05045763
- GLSA-201509-02
- GLSA-201509-02
- https://support.apple.com/kb/HT205031
- https://support.apple.com/kb/HT205031
Modified: 2024-11-21
CVE-2015-3153
The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.
- http://curl.haxx.se/docs/adv_20150429.html
- http://curl.haxx.se/docs/adv_20150429.html
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743
- APPLE-SA-2015-08-13-2
- APPLE-SA-2015-08-13-2
- openSUSE-SU-2015:0861
- openSUSE-SU-2015:0861
- DSA-3240
- DSA-3240
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
- http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
- 74408
- 74408
- 1032233
- 1032233
- USN-2591-1
- USN-2591-1
- https://kc.mcafee.com/corporate/index?page=content&id=SB10131
- https://kc.mcafee.com/corporate/index?page=content&id=SB10131
- https://support.apple.com/kb/HT205031
- https://support.apple.com/kb/HT205031
Modified: 2024-11-21
CVE-2015-3236
cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous connection when reusing a reset (curl_easy_reset) connection handle to send a request to the same host name, which allows remote attackers to obtain sensitive information via unspecified vectors.
- http://curl.haxx.se/docs/adv_20150617A.html
- http://curl.haxx.se/docs/adv_20150617A.html
- FEDORA-2015-10155
- FEDORA-2015-10155
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
- http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html
- 75385
- 75385
- 91787
- 91787
- https://kc.mcafee.com/corporate/index?page=content&id=SB10131
- https://kc.mcafee.com/corporate/index?page=content&id=SB10131
- GLSA-201509-02
- GLSA-201509-02
Modified: 2024-11-21
CVE-2015-3237
The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.
- http://curl.haxx.se/docs/adv_20150617B.html
- http://curl.haxx.se/docs/adv_20150617B.html
- FEDORA-2015-10155
- FEDORA-2015-10155
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- 75387
- 75387
- 91787
- 91787
- 1036371
- 1036371
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05111017
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05111017
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380
- GLSA-201509-02
- GLSA-201509-02
Modified: 2024-11-21
CVE-2016-0755
The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015.
- http://curl.haxx.se/docs/adv_20160127A.html
- http://curl.haxx.se/docs/adv_20160127A.html
- APPLE-SA-2016-09-20
- APPLE-SA-2016-09-20
- FEDORA-2016-3fa315a5dd
- FEDORA-2016-3fa315a5dd
- FEDORA-2016-55137a3adb
- FEDORA-2016-55137a3adb
- FEDORA-2016-5a141de5d9
- FEDORA-2016-5a141de5d9
- FEDORA-2016-57bebab3b6
- FEDORA-2016-57bebab3b6
- openSUSE-SU-2016:0360
- openSUSE-SU-2016:0360
- openSUSE-SU-2016:0373
- openSUSE-SU-2016:0373
- openSUSE-SU-2016:0376
- openSUSE-SU-2016:0376
- http://packetstormsecurity.com/files/135695/Slackware-Security-Advisory-curl-Updates.html
- http://packetstormsecurity.com/files/135695/Slackware-Security-Advisory-curl-Updates.html
- DSA-3455
- DSA-3455
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 82307
- 82307
- 1034882
- 1034882
- SSA:2016-039-01
- SSA:2016-039-01
- USN-2882-1
- USN-2882-1
- GLSA-201701-47
- GLSA-201701-47
- https://support.apple.com/HT207170
- https://support.apple.com/HT207170
Modified: 2024-11-21
CVE-2016-3739
The (1) mbed_connect_step1 function in lib/vtls/mbedtls.c and (2) polarssl_connect_step1 function in lib/vtls/polarssl.c in cURL and libcurl before 7.49.0, when using SSLv3 or making a TLS connection to a URL that uses a numerical IP address, allow remote attackers to spoof servers via an arbitrary valid certificate.
- [oss-security] 20240327 [SECURITY ADVISORY] curl: CVE-2024-2466: TLS certificate check bypass with mbedTLS
- [oss-security] 20240327 [SECURITY ADVISORY] curl: CVE-2024-2466: TLS certificate check bypass with mbedTLS
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 90726
- 90726
- 1035907
- 1035907
- SSA:2016-141-01
- SSA:2016-141-01
- https://curl.haxx.se/changes.html#7_49_0
- https://curl.haxx.se/changes.html#7_49_0
- https://curl.haxx.se/CVE-2016-3739.patch
- https://curl.haxx.se/CVE-2016-3739.patch
- https://curl.haxx.se/docs/adv_20160518.html
- https://curl.haxx.se/docs/adv_20160518.html
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
- GLSA-201701-47
- GLSA-201701-47
Modified: 2024-11-21
CVE-2016-4802
Multiple untrusted search path vulnerabilities in cURL and libcurl before 7.49.1, when built with SSPI or telnet is enabled, allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) security.dll, (2) secur32.dll, or (3) ws2_32.dll in the application or current working directory.
Modified: 2024-11-21
CVE-2016-5419
curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass intended restrictions by resuming a session.
- openSUSE-SU-2016:2227
- openSUSE-SU-2016:2227
- openSUSE-SU-2016:2379
- openSUSE-SU-2016:2379
- RHSA-2016:2575
- RHSA-2016:2575
- RHSA-2016:2957
- RHSA-2016:2957
- DSA-3638
- DSA-3638
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 92292
- 92292
- 92319
- 92319
- 1036538
- 1036538
- 1038341
- 1038341
- SSA:2016-219-01
- SSA:2016-219-01
- USN-3048-1
- USN-3048-1
- RHSA-2018:3558
- RHSA-2018:3558
- https://curl.haxx.se/docs/adv_20160803A.html
- https://curl.haxx.se/docs/adv_20160803A.html
- FEDORA-2016-24316f1f56
- FEDORA-2016-24316f1f56
- FEDORA-2016-8354baae0f
- FEDORA-2016-8354baae0f
- GLSA-201701-47
- GLSA-201701-47
- https://source.android.com/security/bulletin/2016-12-01.html
- https://source.android.com/security/bulletin/2016-12-01.html
- https://www.tenable.com/security/tns-2016-18
- https://www.tenable.com/security/tns-2016-18
Modified: 2024-11-21
CVE-2016-5420
curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously created connection with a different client certificate.
- openSUSE-SU-2016:2227
- openSUSE-SU-2016:2227
- openSUSE-SU-2016:2379
- openSUSE-SU-2016:2379
- RHSA-2016:2575
- RHSA-2016:2575
- RHSA-2016:2957
- RHSA-2016:2957
- DSA-3638
- DSA-3638
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 92309
- 92309
- 1036537
- 1036537
- 1036739
- 1036739
- SSA:2016-219-01
- SSA:2016-219-01
- USN-3048-1
- USN-3048-1
- RHSA-2018:3558
- RHSA-2018:3558
- https://curl.haxx.se/docs/adv_20160803B.html
- https://curl.haxx.se/docs/adv_20160803B.html
- FEDORA-2016-24316f1f56
- FEDORA-2016-24316f1f56
- FEDORA-2016-8354baae0f
- FEDORA-2016-8354baae0f
- GLSA-201701-47
- GLSA-201701-47
- https://source.android.com/security/bulletin/2016-12-01.html
- https://source.android.com/security/bulletin/2016-12-01.html
- https://www.tenable.com/security/tns-2016-18
- https://www.tenable.com/security/tns-2016-18
Modified: 2024-11-21
CVE-2016-5421
Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact via unknown vectors.
- openSUSE-SU-2016:2227
- openSUSE-SU-2016:2227
- openSUSE-SU-2016:2379
- openSUSE-SU-2016:2379
- DSA-3638
- DSA-3638
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 92306
- 92306
- 1036536
- 1036536
- SSA:2016-219-01
- SSA:2016-219-01
- USN-3048-1
- USN-3048-1
- RHSA-2018:3558
- RHSA-2018:3558
- https://curl.haxx.se/docs/adv_20160803C.html
- https://curl.haxx.se/docs/adv_20160803C.html
- FEDORA-2016-24316f1f56
- FEDORA-2016-24316f1f56
- FEDORA-2016-8354baae0f
- FEDORA-2016-8354baae0f
- GLSA-201701-47
- GLSA-201701-47
- https://source.android.com/security/bulletin/2016-12-01.html
- https://source.android.com/security/bulletin/2016-12-01.html
- https://www.tenable.com/security/tns-2016-18
- https://www.tenable.com/security/tns-2016-18
Modified: 2024-11-21
CVE-2016-7141
curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.
- openSUSE-SU-2016:2379
- openSUSE-SU-2016:2379
- RHSA-2016:2575
- RHSA-2016:2575
- RHSA-2016:2957
- RHSA-2016:2957
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 92754
- 92754
- 1036739
- 1036739
- RHSA-2018:3558
- RHSA-2018:3558
- https://bugzilla.redhat.com/show_bug.cgi?id=1373229
- https://bugzilla.redhat.com/show_bug.cgi?id=1373229
- https://curl.haxx.se/docs/adv_20160907.html
- https://curl.haxx.se/docs/adv_20160907.html
- https://github.com/curl/curl/commit/curl-7_50_2~32
- https://github.com/curl/curl/commit/curl-7_50_2~32
- [debian-lts-announce] 20181106 [SECURITY] [DLA 1568-1] curl security update
- [debian-lts-announce] 20181106 [SECURITY] [DLA 1568-1] curl security update
- GLSA-201701-47
- GLSA-201701-47
Modified: 2024-11-21
CVE-2016-7167
Multiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) curl_unescape, and (4) curl_easy_unescape functions in libcurl before 7.50.3 allow attackers to have unspecified impact via a string of length 0xffffffff, which triggers a heap-based buffer overflow.
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 92975
- 92975
- 1036813
- 1036813
- SSA:2016-259-01
- SSA:2016-259-01
- RHSA-2017:2016
- RHSA-2017:2016
- RHSA-2018:2486
- RHSA-2018:2486
- RHSA-2018:3558
- RHSA-2018:3558
- https://curl.haxx.se/docs/adv_20160914.html
- https://curl.haxx.se/docs/adv_20160914.html
- [debian-lts-announce] 20181106 [SECURITY] [DLA 1568-1] curl security update
- [debian-lts-announce] 20181106 [SECURITY] [DLA 1568-1] curl security update
- FEDORA-2016-08533fc59c
- FEDORA-2016-08533fc59c
- FEDORA-2016-7a2ed52d41
- FEDORA-2016-7a2ed52d41
- FEDORA-2016-80f4f71eff
- FEDORA-2016-80f4f71eff
- GLSA-201701-47
- GLSA-201701-47
Modified: 2024-11-21
CVE-2016-8615
A flaw was found in curl before version 7.51. If cookie state is written into a cookie jar file that is later read back and used for subsequent requests, a malicious HTTP server can inject new cookies for arbitrary domains into said cookie jar.
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 94096
- 94096
- 1037192
- 1037192
- RHSA-2018:2486
- RHSA-2018:2486
- RHSA-2018:3558
- RHSA-2018:3558
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8615
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8615
- https://curl.haxx.se/CVE-2016-8615.patch
- https://curl.haxx.se/CVE-2016-8615.patch
- https://curl.haxx.se/docs/adv_20161102A.html
- https://curl.haxx.se/docs/adv_20161102A.html
- [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- GLSA-201701-47
- GLSA-201701-47
- https://www.tenable.com/security/tns-2016-21
- https://www.tenable.com/security/tns-2016-21
Modified: 2024-11-21
CVE-2016-8616
A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and password with the existing connections. This means that if an unused connection with proper credentials exists for a protocol that has connection-scoped credentials, an attacker can cause that connection to be reused if s/he knows the case-insensitive version of the correct password.
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 94094
- 94094
- 1037192
- 1037192
- RHSA-2018:2486
- RHSA-2018:2486
- RHSA-2018:3558
- RHSA-2018:3558
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8616
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8616
- https://curl.haxx.se/CVE-2016-8616.patch
- https://curl.haxx.se/CVE-2016-8616.patch
- https://curl.haxx.se/docs/adv_20161102B.html
- https://curl.haxx.se/docs/adv_20161102B.html
- GLSA-201701-47
- GLSA-201701-47
- https://www.tenable.com/security/tns-2016-21
- https://www.tenable.com/security/tns-2016-21
Modified: 2024-11-21
CVE-2016-8617
The base64 encode function in curl before version 7.51.0 is prone to a buffer being under allocated in 32bit systems if it receives at least 1Gb as input via `CURLOPT_USERNAME`.
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 94097
- 94097
- 1037192
- 1037192
- RHSA-2018:2486
- RHSA-2018:2486
- RHSA-2018:3558
- RHSA-2018:3558
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8617
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8617
- https://curl.haxx.se/CVE-2016-8617.patch
- https://curl.haxx.se/CVE-2016-8617.patch
- https://curl.haxx.se/docs/adv_20161102C.html
- https://curl.haxx.se/docs/adv_20161102C.html
- [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- GLSA-201701-47
- GLSA-201701-47
- https://www.tenable.com/security/tns-2016-21
- https://www.tenable.com/security/tns-2016-21
Modified: 2024-11-21
CVE-2016-8618
The libcurl API function called `curl_maprintf()` before version 7.51.0 can be tricked into doing a double-free due to an unsafe `size_t` multiplication, on systems using 32 bit `size_t` variables.
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 94098
- 94098
- 1037192
- 1037192
- RHSA-2018:2486
- RHSA-2018:2486
- RHSA-2018:3558
- RHSA-2018:3558
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8618
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8618
- https://curl.haxx.se/docs/adv_20161102D.html
- https://curl.haxx.se/docs/adv_20161102D.html
- GLSA-201701-47
- GLSA-201701-47
- https://www.tenable.com/security/tns-2016-21
- https://www.tenable.com/security/tns-2016-21
Modified: 2024-11-21
CVE-2016-8619
The function `read_data()` in security.c in curl before version 7.51.0 is vulnerable to memory double free.
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 94100
- 94100
- 1037192
- 1037192
- RHSA-2018:2486
- RHSA-2018:2486
- RHSA-2018:3558
- RHSA-2018:3558
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8619
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8619
- https://curl.haxx.se/CVE-2016-8619.patch
- https://curl.haxx.se/CVE-2016-8619.patch
- https://curl.haxx.se/docs/adv_20161102E.html
- https://curl.haxx.se/docs/adv_20161102E.html
- GLSA-201701-47
- GLSA-201701-47
- https://www.tenable.com/security/tns-2016-21
- https://www.tenable.com/security/tns-2016-21
Modified: 2024-11-21
CVE-2016-8620
The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read via user controlled input.
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 94102
- 94102
- 1037192
- 1037192
- RHSA-2018:3558
- RHSA-2018:3558
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8620
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8620
- https://curl.haxx.se/docs/adv_20161102F.html
- https://curl.haxx.se/docs/adv_20161102F.html
- GLSA-201701-47
- GLSA-201701-47
- https://www.tenable.com/security/tns-2016-21
- https://www.tenable.com/security/tns-2016-21
Modified: 2024-11-21
CVE-2016-8621
The `curl_getdate` function in curl before version 7.51.0 is vulnerable to an out of bounds read if it receives an input with one digit short.
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 94101
- 94101
- 1037192
- 1037192
- RHSA-2018:2486
- RHSA-2018:2486
- RHSA-2018:3558
- RHSA-2018:3558
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8621
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8621
- https://curl.haxx.se/CVE-2016-8621.patch
- https://curl.haxx.se/CVE-2016-8621.patch
- https://curl.haxx.se/docs/adv_20161102G.html
- https://curl.haxx.se/docs/adv_20161102G.html
- GLSA-201701-47
- GLSA-201701-47
- https://www.tenable.com/security/tns-2016-21
- https://www.tenable.com/security/tns-2016-21
Modified: 2024-11-21
CVE-2016-8622
The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if this function would be made to allocate a unscape destination buffer larger than 2GB, it would return that new length in a signed 32 bit integer variable, thus the length would get either just truncated or both truncated and turned negative. That could then lead to libcurl writing outside of its heap based buffer.
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 94105
- 94105
- 1037192
- 1037192
- RHSA-2018:2486
- RHSA-2018:2486
- RHSA-2018:3558
- RHSA-2018:3558
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8622
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8622
- https://curl.haxx.se/docs/adv_20161102H.html
- https://curl.haxx.se/docs/adv_20161102H.html
- GLSA-201701-47
- GLSA-201701-47
- https://www.tenable.com/security/tns-2016-21
- https://www.tenable.com/security/tns-2016-21
Modified: 2024-11-21
CVE-2016-8623
A flaw was found in curl before version 7.51.0. The way curl handles cookies permits other threads to trigger a use-after-free leading to information disclosure.
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 94106
- 94106
- 1037192
- 1037192
- RHSA-2018:2486
- RHSA-2018:2486
- RHSA-2018:3558
- RHSA-2018:3558
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8623
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8623
- https://curl.haxx.se/CVE-2016-8623.patch
- https://curl.haxx.se/CVE-2016-8623.patch
- https://curl.haxx.se/docs/adv_20161102I.html
- https://curl.haxx.se/docs/adv_20161102I.html
- [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- GLSA-201701-47
- GLSA-201701-47
- https://www.tenable.com/security/tns-2016-21
- https://www.tenable.com/security/tns-2016-21
Modified: 2024-11-21
CVE-2016-8624
curl before version 7.51.0 doesn't parse the authority component of the URL correctly when the host name part ends with a '#' character, and could instead be tricked into connecting to a different host. This may have security implications if you for example use an URL parser that follows the RFC to check for allowed domains before using curl to request them.
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 94103
- 94103
- 1037192
- 1037192
- RHSA-2018:2486
- RHSA-2018:2486
- RHSA-2018:3558
- RHSA-2018:3558
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8624
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8624
- https://curl.haxx.se/docs/adv_20161102J.html
- https://curl.haxx.se/docs/adv_20161102J.html
- [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [pulsar-commits] 20200914 [GitHub] [pulsar] klwilson227 opened a new issue #8061: CVE-2017-14063
- [pulsar-commits] 20200914 [GitHub] [pulsar] klwilson227 opened a new issue #8061: CVE-2017-14063
- GLSA-201701-47
- GLSA-201701-47
- https://www.tenable.com/security/tns-2016-21
- https://www.tenable.com/security/tns-2016-21
Modified: 2024-11-21
CVE-2016-8625
curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowingly issue network transfer requests to the wrong host.
- 94107
- 94107
- 1037192
- 1037192
- RHSA-2018:2486
- RHSA-2018:2486
- RHSA-2018:3558
- RHSA-2018:3558
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8625
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8625
- https://curl.haxx.se/CVE-2016-8625.patch
- https://curl.haxx.se/CVE-2016-8625.patch
- https://curl.haxx.se/docs/adv_20161102K.html
- https://curl.haxx.se/docs/adv_20161102K.html
- [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- GLSA-201701-47
- GLSA-201701-47
- https://www.tenable.com/security/tns-2016-21
- https://www.tenable.com/security/tns-2016-21
Modified: 2024-11-21
CVE-2016-9586
curl before version 7.52.0 is vulnerable to a buffer overflow when doing a large floating point output in libcurl's implementation of the printf() functions. If there are any application that accepts a format string from the outside without necessary input filtering, it could allow remote attacks.
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 95019
- 95019
- 1037515
- 1037515
- RHSA-2018:3558
- RHSA-2018:3558
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9586
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9586
- https://curl.haxx.se/docs/adv_20161221A.html
- https://curl.haxx.se/docs/adv_20161221A.html
- https://github.com/curl/curl/commit/curl-7_51_0-162-g3ab3c16
- https://github.com/curl/curl/commit/curl-7_51_0-162-g3ab3c16
- [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [debian-lts-announce] 20181106 [SECURITY] [DLA 1568-1] curl security update
- [debian-lts-announce] 20181106 [SECURITY] [DLA 1568-1] curl security update
- GLSA-201701-47
- GLSA-201701-47
Modified: 2024-11-21
CVE-2016-9594
curl before version 7.52.1 is vulnerable to an uninitialized random in libcurl's internal function that returns a good 32bit random value. Having a weak or virtually non-existent random value makes the operations that use it vulnerable.
- 95094
- 95094
- 1037528
- 1037528
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9594
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9594
- https://curl.haxx.se/docs/adv_20161223.html
- https://curl.haxx.se/docs/adv_20161223.html
- GLSA-201701-47
- GLSA-201701-47
- https://www.tenable.com/security/tns-2017-04
- https://www.tenable.com/security/tns-2017-04
Modified: 2024-11-21
CVE-2017-1000099
When asking to get a file from a file:// URL, libcurl provides a feature that outputs meta-data about the file using HTTP-like headers. The code doing this would send the wrong buffer to the user (stdout or the application's provide callback), which could lead to other private data from the heap to get inadvertently displayed. The wrong buffer was an uninitialized memory area allocated on the heap and if it turned out to not contain any zero byte, it would continue and display the data following that buffer in memory.
Modified: 2024-11-21
CVE-2017-1000100
When doing a TFTP transfer and curl/libcurl is given a URL that contains a very long file name (longer than about 515 bytes), the file name is truncated to fit within the buffer boundaries, but the buffer size is still wrongly updated to use the untruncated length. This too large value is then used in the sendto() call, making curl attempt to send more data than what is actually put into the buffer. The endto() function will then read beyond the end of the heap based buffer. A malicious HTTP(S) server could redirect a vulnerable libcurl-using client to a crafted TFTP URL (if the client hasn't restricted which protocols it allows redirects to) and trick it to send private memory contents to a remote server over UDP. Limit curl's redirect protocols with --proto-redir and libcurl's with CURLOPT_REDIR_PROTOCOLS.
Modified: 2024-11-21
CVE-2017-1000101
curl supports "globbing" of URLs, in which a user can pass a numerical range to have the tool iterate over those numbers to do a sequence of transfers. In the globbing function that parses the numerical range, there was an omission that made curl read a byte beyond the end of the URL if given a carefully crafted, or just wrongly written, URL. The URL is stored in a heap based buffer, so it could then be made to wrongly read something else instead of crashing. An example of a URL that triggers the flaw would be `http://ur%20[0-60000000000000000000`.
Modified: 2024-11-21
CVE-2017-1000254
libcurl may read outside of a heap allocated buffer when doing FTP. When libcurl connects to an FTP server and successfully logs in (anonymous or not), it asks the server for the current directory with the `PWD` command. The server then responds with a 257 response containing the path, inside double quotes. The returned path name is then kept by libcurl for subsequent uses. Due to a flaw in the string parser for this directory name, a directory name passed like this but without a closing double quote would lead to libcurl not adding a trailing NUL byte to the buffer holding the name. When libcurl would then later access the string, it could read beyond the allocated heap buffer and crash or wrongly access data beyond the buffer, thinking it was part of the path. A malicious server could abuse this fact and effectively prevent libcurl-based clients to work with it - the PWD command is always issued on new FTP connections and the mistake has a high chance of causing a segfault. The simple fact that this has issue remained undiscovered for this long could suggest that malformed PWD responses are rare in benign servers. We are not aware of any exploit of this flaw. This bug was introduced in commit [415d2e7cb7](https://github.com/curl/curl/commit/415d2e7cb7), March 2005. In libcurl version 7.56.0, the parser always zero terminates the string but also rejects it if not terminated properly with a final double quote.
- DSA-3992
- DSA-3992
- 101115
- 101115
- 1039509
- 1039509
- RHSA-2018:2486
- RHSA-2018:2486
- RHSA-2018:3558
- RHSA-2018:3558
- https://curl.haxx.se/673d0cd8.patch
- https://curl.haxx.se/673d0cd8.patch
- https://curl.haxx.se/docs/adv_20171004.html
- https://curl.haxx.se/docs/adv_20171004.html
- [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8
- GLSA-201712-04
- GLSA-201712-04
- https://support.apple.com/HT208331
- https://support.apple.com/HT208331
Modified: 2024-11-21
CVE-2017-1000257
An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl would pass on that (non-existing) data with a pointer and the size (zero) to the deliver-data function. libcurl's deliver-data function treats zero as a magic number and invokes strlen() on the data to figure out the length. The strlen() is called on a heap based buffer that might not be zero terminated so libcurl might read beyond the end of it into whatever memory lies after (or just crash) and then deliver that to the application as if it was actually downloaded.
Modified: 2024-11-21
CVE-2017-2629
curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the server's certificate's validity in the code that checks for a test success or failure. It ends up always thinking there's valid proof, even when there is none or if the server doesn't support the TLS extension in question. This could lead to users not detecting when a server's certificate goes invalid or otherwise be mislead that the server is in a better shape than it is in reality. This flaw also exists in the command line tool (--cert-status).
- 96382
- 96382
- 1037871
- 1037871
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2629
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2629
- https://curl.haxx.se/docs/adv_20170222.html
- https://curl.haxx.se/docs/adv_20170222.html
- GLSA-201703-04
- GLSA-201703-04
- https://www.tenable.com/security/tns-2017-09
- https://www.tenable.com/security/tns-2017-09
Modified: 2024-11-21
CVE-2017-9502
In curl before 7.54.1 on Windows and DOS, libcurl's default protocol function, which is the logic that allows an application to set which protocol libcurl should attempt to use when given a URL without a scheme part, had a flaw that could lead to it overwriting a heap based memory buffer with seven bytes. If the default protocol is specified to be FILE or a file: URL lacks two slashes, the given "URL" starts with a drive letter, and libcurl is built for Windows or DOS, then libcurl would copy the path 7 bytes off, so that the end of the given path would write beyond the malloc buffer (7 bytes being the length in bytes of the ascii string "file://").
Closed bugs
sssd не перезапускается при обновлении (до sssd-1.15.3-alt1.M80P.1)
logrotate из коробки не хочет ротировать sssd логи