USN-484-1: curl vulnerability
17 July 2007
curl vulnerability
Releases
Details
It was discovered that the GnuTLS certificate verification methods
implemented in Curl did not check for expiration and activation dates.
When performing validations, tools using libcurl3-gnutls would
incorrectly allow connections to sites using expired certificates.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 7.04
-
libcurl3-gnutls
-
7.15.5-1ubuntu2.1
Ubuntu 6.10
-
libcurl3-gnutls
-
7.15.4-1ubuntu2.2
Ubuntu 6.06
-
libcurl3-gnutls
-
7.15.1-1ubuntu2.1
After a standard system upgrade you need to reboot your computer to
effect the necessary changes.