Red Hat Security Advisory 2019-2181-01 - The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP. A heap-based buffer overread has been addressed.
e60924c1ef05768c79b8e3a83a192797600c80f6d899f87136e2fcd2348d5cb9
Gentoo Linux Security Advisory 201903-3 - Multiple vulnerabilities have been found in cURL, the worst of which could result in a Denial of Service condition. Versions less than 7.64.0 are affected.
7b295ee612fd47e8561e865b6ce95775caadd490653734d95071b885946efb5a
Ubuntu Security Notice 3805-2 - USN-3805-1 fixed a vulnerability in curl. This update provides the corresponding update for Ubuntu 12.04 ESM. Brian Carpenter discovered that the curl command-line tool incorrectly handled error messages. A remote attacker could possibly use this issue to obtain sensitive information. Various other issues were also addressed.
35d25f9232b841e63a7b4d0ebceb8103967774d6ded9953dc4c4a7ebc1414ddb
Debian Linux Security Advisory 4331-1 - Two vulnerabilities were discovered in cURL, an URL transfer library.
e4ffca0478e4be4c0b90134f934441cb4379f22ee99443a26e86fee8f3061def
Slackware Security Advisory - New curl packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
65f4dbc81ad891a30f90da807afd6698f33572afbe3c1ad0ca72642554585a0e
Ubuntu Security Notice 3805-1 - Harry Sintonen discovered that curl incorrectly handled SASL authentication. A remote attacker could use this issue to cause curl to crash, resulting in a denial of service, or possibly execute arbitrary code. Brian Carpenter discovered that curl incorrectly handled memory when closing certain handles. A remote attacker could use this issue to cause curl to crash, resulting in a denial of service, or possibly execute arbitrary code. Various other issues were also addressed.
d55ced143953522e7a9be8d94b62af9c7f502fd22672af3f7506ef921fcbe897