Ubuntu Security Notice USN-5412-1

Discussion in 'News Aggregator' started by Packet Storm, 12 May 2022.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 5412-1 - Axel Chong discovered that curl incorrectly handled percent-encoded URL separators. A remote attacker could possibly use this issue to trick curl into using the wrong URL and bypass certain checks or filters. This issue only affected Ubuntu 22.04 LTS. Florian Kohnhuser discovered that curl incorrectly handled returning a TLS server's certificate chain details. A remote attacker could possibly use this issue to cause curl to stop responding, resulting in a denial of service.

    Continue reading...
     

Share This Page

Loading...