Updated curl packages fix security vulnerabilities
Publication date: 12 Apr 2021Modification date: 12 Apr 2021
Type: security
Affected Mageia releases : 7 , 8
CVE: CVE-2021-22876 , CVE-2021-22890
Description
libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request. (CVE-2021-22876) TLS 1.3 session ticket proxy host mixup. (CVE-2021-22890)
References
SRPMS
7/core
- curl-7.71.0-1.2.mga7
8/core
- curl-7.74.0-1.1.mga8