Debian Security Advisory
DLA-1121-1 curl -- LTS security update
- Date Reported:
- 05 Oct 2017
- Affected Packages:
- curl
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2017-1000254.
- More information:
-
It was discovered that there was a out-of-bounds read vulnerability in curl, a command-line and library for transferring data over HTTP/FTP, etc. A malicious FTP server could abuse this to prevent curl-based clients from interacting with it.
See https://curl.haxx.se/docs/adv_20171004.html for more details.
For Debian 7
Wheezy
, this issue has been fixed in curl version 7.26.0-1+wheezy21.We recommend that you upgrade your curl packages.