RHSA-2023:4139: Moderate: curl security update
Moderate: curl security update
Other sources
The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.Security Fix(es): curl: POST following PUT confusion (CVE-2022-32221) curl: HTTP multi-header compression denial of service (CVE-2023-23916) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:4139?
RHSA-2023:4139 is classified as a moderate security vulnerability.
How do I fix RHSA-2023:4139?
To address RHSA-2023:4139, update the curl package to version 7.76.1-14.el9_0.6 or later.
What type of vulnerabilities are fixed in RHSA-2023:4139?
RHSA-2023:4139 addresses vulnerabilities related to POST following PUT confusion as identified by CVE-2022-32221.
Which versions of Red Hat Enterprise Linux are affected by RHSA-2023:4139?
RHSA-2023:4139 affects multiple versions of Red Hat Enterprise Linux including those for x86_64, Power, and IBM z Systems.
What packages are included in the RHSA-2023:4139 update?
The RHSA-2023:4139 update includes curl, libcurl, and their respective debuginfo and minimal packages.