From 4f2d7949f03e1c198bc888f2d05f421d35c57e21 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Mon, 9 Oct 2017 18:53:29 +0100 Subject: reinit the tree, so we can have metadata --- metadata/glsa/glsa-201401-14.xml | 59 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 59 insertions(+) create mode 100644 metadata/glsa/glsa-201401-14.xml (limited to 'metadata/glsa/glsa-201401-14.xml') diff --git a/metadata/glsa/glsa-201401-14.xml b/metadata/glsa/glsa-201401-14.xml new file mode 100644 index 000000000000..d6df9702abb9 --- /dev/null +++ b/metadata/glsa/glsa-201401-14.xml @@ -0,0 +1,59 @@ + + + + cURL: Multiple vulnerabilities + Multiple vulnerabilities have been found in cURL, allowing + attackers to execute arbitrary code or cause Denial of Service. + + curl + 2014-01-20 + 2014-01-20: 1 + 456074 + 465678 + 474354 + 492688 + 497092 + remote + + + 7.34.0-r1 + 7.34.0-r1 + + + +

cURL is a command line tool for transferring files with URL syntax, + supporting numerous protocols. +

+
+ +

Multiple vulnerabilities have been discovered in cURL. Please review the + CVE identifiers referenced below for details. +

+
+ +

A remote attacker could entice a user or automated process to connect to + a malicious server using cURL, possibly resulting in the remote execution + of arbitrary code or a Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All cURL users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-misc/curl-7.34.0-r1" + + +
+ + CVE-2013-0249 + CVE-2013-1944 + CVE-2013-2174 + CVE-2013-6422 + + ackle + ackle +
-- cgit v1.2.3