USN-3598-1

Source
https://ubuntu.com/security/notices/USN-3598-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/USN-3598-1.json
Related
Published
2018-03-15T12:02:23.243935Z
Modified
2018-03-15T12:02:23.243935Z
Details

Phan Thanh discovered that curl incorrectly handled certain FTP paths. An attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2018-1000120)

Dario Weisser discovered that curl incorrectly handled certain LDAP URLs. An attacker could possibly use this issue to cause a denial of service. (CVE-2018-1000121)

Max Dymond discovered that curl incorrectly handled certain RTSP data. An attacker could possibly use this to cause a denial of service or even to get access to sensitive data. (CVE-2018-1000122)

References

Affected packages

Ubuntu:14.04:LTS / curl

Package

Name
curl

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
7.35.0-1ubuntu2.15

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "curl-udeb": "7.35.0-1ubuntu2.15",
            "libcurl3-udeb": "7.35.0-1ubuntu2.15",
            "curl": "7.35.0-1ubuntu2.15",
            "libcurl3": "7.35.0-1ubuntu2.15",
            "libcurl4-gnutls-dev": "7.35.0-1ubuntu2.15",
            "libcurl3-gnutls": "7.35.0-1ubuntu2.15",
            "libcurl4-doc": "7.35.0-1ubuntu2.15",
            "libcurl3-nss": "7.35.0-1ubuntu2.15",
            "libcurl4-nss-dev": "7.35.0-1ubuntu2.15",
            "libcurl4-openssl-dev": "7.35.0-1ubuntu2.15"
        }
    ]
}

Ubuntu:16.04:LTS / curl

Package

Name
curl

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
7.47.0-1ubuntu2.7

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "curl": "7.47.0-1ubuntu2.7",
            "libcurl3": "7.47.0-1ubuntu2.7",
            "libcurl4-gnutls-dev": "7.47.0-1ubuntu2.7",
            "libcurl3-gnutls": "7.47.0-1ubuntu2.7",
            "libcurl4-doc": "7.47.0-1ubuntu2.7",
            "libcurl3-nss": "7.47.0-1ubuntu2.7",
            "libcurl4-nss-dev": "7.47.0-1ubuntu2.7",
            "libcurl4-openssl-dev": "7.47.0-1ubuntu2.7"
        }
    ]
}