USN-4402-1: curl vulnerabilities

24 June 2020

curl vulnerabilities

Packages

  • curl - HTTP, HTTPS, and FTP client and client libraries

Details

Marek Szlagor, Gregory Jefferis and Jeroen Ooms discovered
that curl incorrectly handled certain credentials. An attacker
could possibly use this issue to expose sensitive information.
This issue only affected Ubuntu 19.10 and Ubuntu 20.04 LTS.
(CVE-2020-8169)

It was discovered that curl incorrectly handled certain parameters.
An attacker could possibly use this issue to overwrite a local file.
(CVE-2020-8177)