Release Info

Advisory: CLSA-2022:1643198583

OS: CentOS 8.4 ELS

Public date: 2022-01-26 00:00:00

Project: curl

Version: 7.61.1-18.el8.4.2.tuxcare.els1

Errata link: https://errata.tuxcare.com/els_os/centos8.4els/CLSA-2022-1643198583.html

Changelog

- CVE-2021-22925: fix TELNET stack contents disclosure again - CVE-2021-22898: fix TELNET stack contents disclosure - CVE-2021-22876: prevent automatic referer from leaking credentials

Update

Update command: dnf update curl*

Packages list

libcurl-devel-7.61.1-18.el8.4.2.tuxcare.els1.x86_64.rpm libcurl-minimal-7.61.1-18.el8.4.2.tuxcare.els1.i686.rpm libcurl-devel-7.61.1-18.el8.4.2.tuxcare.els1.i686.rpm libcurl-7.61.1-18.el8.4.2.tuxcare.els1.x86_64.rpm curl-7.61.1-18.el8.4.2.tuxcare.els1.x86_64.rpm libcurl-minimal-7.61.1-18.el8.4.2.tuxcare.els1.x86_64.rpm libcurl-7.61.1-18.el8.4.2.tuxcare.els1.i686.rpm curl-minimal-7.61.1-18.el8.4.2.tuxcare.els1.x86_64.rpm

CVEs

CVE-2021-22898
CVE-2021-22876
CVE-2021-22925