CVE-2014-3707
curl - security update
EPSS 5.1%
描述
The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to read sensitive memory information.
如何修補 CVE-2014-3707
要修補 CVE-2014-3707,請將受影響套件升級到下列已修補版本。
- Debian/curl—升級至 7.38.0-3 或更新版本
- Debian/curl—升級至 7.21.0-2.1+squeeze10 或更新版本
- Debian/curl—升級至 7.26.0-1+wheezy11 或更新版本
CVE-2014-3707 正在被利用嗎?
中等 — EPSS 為 5.1%,可持續追蹤但非最高優先。
受影響套件(3)
- from 0, < 7.38.0-3
- from 0, < 7.21.0-2.1+squeeze10
- from 0, < 7.26.0-1+wheezy11