Oracle Linux 7.4 - Vulnerability Inquiries
Hi,
I scanned our system for vulnerabilities using "Qualys Guard" that the following packages are vulnerable:
- curl 7.29.0
cURL Multiple Security VulnerabilitiesQID: 370198Category: LocalCVE ID: CVE-2016-8615, CVE-2016-8616, CVE-2016-8617, CVE-2016-8618, CVE-2016-8619, CVE-2016-8620,CVE-2016-8621, CVE-2016-8622, CVE-2016-8623, CVE-2016-8624, CVE-2016-8625Vendor Reference: cURL 7.51.0Bugtraq ID: 94100, 94102, 94101, 94105, 94106, 94103, 94107, 94096, 94094, 94097, 94098Service Modified: 03/02/2017User Modified: -Edited: NoPCI Vuln: YesTHREAT:cURL is a computer software project providing a library and command-line tool for transferring data using various protocols.cURL contains the following vulnerabilities:CVE-2016-8615: If cookie state is written into a cookie jar file that is later read back and used for subsequent requests, a malicious HTTP server caninject new cookies for arbitrary domains into said cookie jar.CVE-2016-8616: When re-using a connection, curl was
Tagged:
0