Release Info

Advisory: CLSA-2021:1617285762

OS: CentOS 6 ELS

Public date: 2021-04-01 00:00:00

Project: curl

Version: 7.19.7-56.el6.cloudlinux.els6

Errata link: https://errata.tuxcare.com/els_os/centos6els/CLSA-2021-1617285762.html

Changelog

- back-port urlapi from v7.75.0 (used by CVE-2021-22876) - strip credentials from the auto-referer header (CVE-2021-22876)

Update

Packages list

libcurl-devel-7.19.7-56.el6.cloudlinux.els6.x86_64.rpm curl-7.19.7-56.el6.cloudlinux.els6.x86_64.rpm libcurl-7.19.7-56.el6.cloudlinux.els6.i686.rpm libcurl-7.19.7-56.el6.cloudlinux.els6.x86_64.rpm libcurl-devel-7.19.7-56.el6.cloudlinux.els6.i686.rpm

CVEs

CVE-2021-22876