Fixing curl URL sanitizing vulnerability and SSL weakness
The following vulnerabilities have been fixed in curl:
- IMAP, POP3 and SMTP URL sanitization vulnerability
(CVE-2012-0036)
- disable SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS (CVE-2011-3389)
- disable SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG option
for older openssl versions (CVE-2010-4180)
-
Submitted by
Adrian Schröter (adrianSuSE)
- Version 5702
Fixed bugs
bnc#740452
VUL-0: curl: URL sanitizing vulnerability
bnc#742306
VUL-0: curl sets SSL_OP_ALL