Debian Security Advisory

DLA-1121-1 curl -- LTS security update

Date Reported:
05 Oct 2017
Affected Packages:
curl
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2017-1000254.
More information:

It was discovered that there was a out-of-bounds read vulnerability in curl, a command-line and library for transferring data over HTTP/FTP, etc. A malicious FTP server could abuse this to prevent curl-based clients from interacting with it.

See https://curl.haxx.se/docs/adv_20171004.html for more details.

For Debian 7 Wheezy, this issue has been fixed in curl version 7.26.0-1+wheezy21.

We recommend that you upgrade your curl packages.