curl (SL7)

Synopsis: Low: curl security and bug fix update
Advisory ID: SLSA-2019:1880-1
Issue Date: 2019-07-29
CVE Numbers: CVE-2018-14618

The curl packages provide the libcurl library and the curl utility for
downloading files from servers using various protocols, including HTTP,
FTP, and LDAP.

Security Fix(es):

* curl: NTLM password overflow via integer overflow (CVE-2018-14618)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Bug Fix(es):

* baseurl with file:// hangs and then timeout in yum repo (BZ#1709474)

* curl crashes on http links with rate-limit (BZ#1711914)

SL7
x86_64
curl-7.29.0-51.el7_6.3.x86_64.rpm
curl-debuginfo-7.29.0-51.el7_6.3.i686.rpm
curl-debuginfo-7.29.0-51.el7_6.3.x86_64.rpm
libcurl-7.29.0-51.el7_6.3.i686.rpm
libcurl-7.29.0-51.el7_6.3.x86_64.rpm
libcurl-devel-7.29.0-51.el7_6.3.i686.rpm
libcurl-devel-7.29.0-51.el7_6.3.x86_64.rpm

– Scientific Linux Development Team