Synopsis: Low: curl security and bug fix update
Advisory ID: SLSA-2019:1880-1
Issue Date: 2019-07-29
CVE Numbers: CVE-2018-14618
The curl packages provide the libcurl library and the curl utility for
downloading files from servers using various protocols, including HTTP,
FTP, and LDAP.
* curl: NTLM password overflow via integer overflow (CVE-2018-14618)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
* baseurl with file:// hangs and then timeout in yum repo (BZ#1709474)
* curl crashes on http links with rate-limit (BZ#1711914)
– Scientific Linux Development Team