Release Info

Advisory: CLSA-2021:1634922432

OS: Oracle Linux 6 ELS

Public date: 2021-10-22 00:00:00

Project: curl

Version: 7.19.7-56.el6.cloudlinux.ol.els6

Errata link: https://errata.cloudlinux.com/ol6/CLSA-2021-1634922432.html

Changelog

- back-port urlapi from v7.75.0 (used by CVE-2021-22876) - strip credentials from the auto-referer header (CVE-2021-22876)

Update

Packages list

libcurl-devel-7.19.7-56.el6.cloudlinux.ol.els6.x86_64.rpm libcurl-devel-7.19.7-56.el6.cloudlinux.ol.els6.i686.rpm curl-7.19.7-56.el6.cloudlinux.ol.els6.x86_64.rpm libcurl-7.19.7-56.el6.cloudlinux.ol.els6.i686.rpm libcurl-7.19.7-56.el6.cloudlinux.ol.els6.x86_64.rpm

CVEs

CVE-2021-22876