Advisories ยป MGASA-2021-0186

Updated curl packages fix security vulnerabilities

Publication date: 12 Apr 2021
Modification date: 12 Apr 2021
Type: security
Affected Mageia releases : 7 , 8
CVE: CVE-2021-22876 , CVE-2021-22890

Description

libcurl does not strip off user credentials from the URL when automatically
populating the Referer: HTTP request header field in outgoing HTTP requests,
and therefore risks leaking sensitive data to the server that is the target of
the second HTTP request. (CVE-2021-22876)

TLS 1.3 session ticket proxy host mixup. (CVE-2021-22890)
                

References

SRPMS

7/core

8/core