Bug 928533 - (CVE-2015-3153) VUL-1: CVE-2015-3153: curl: sensitive HTTP server headers also sent to proxies
(CVE-2015-3153)
VUL-1: CVE-2015-3153: curl: sensitive HTTP server headers also sent to proxies
Status: RESOLVED FIXED
: 930239 (view as bug list)
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Normal
: ---
Assigned To: Security Team bot
Security Team bot
maint:released:sle10-sp3:61668 maint:...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2015-04-24 12:23 UTC by Marcus Meissner
Modified: 2019-06-17 22:44 UTC (History)
4 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Marcus Meissner 2015-04-24 12:24:31 UTC
https://github.com/bagder/curl/issues/236
Comment 5 Swamp Workflow Management 2015-04-24 22:00:38 UTC
bugbot adjusting priority
Comment 6 Vítězslav Čížek 2015-04-29 08:38:19 UTC
curl 7.42.1 is out.
Advisory: http://curl.haxx.se/docs/adv_20150429.html
Comment 7 Bernhard Wiedemann 2015-04-29 10:00:08 UTC
This is an autogenerated message for OBS integration:
This bug (928533) was mentioned in
https://build.opensuse.org/request/show/304524 13.2+13.1 / curl
Comment 15 Bernhard Wiedemann 2015-05-08 19:40:22 UTC
*** Bug 930239 has been marked as a duplicate of this bug. ***
Comment 16 Swamp Workflow Management 2015-05-12 15:08:05 UTC
openSUSE-SU-2015:0861-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 928533
CVE References: CVE-2015-3153
Sources used:
openSUSE 13.2 (src):    curl-7.42.1-11.1
openSUSE 13.1 (src):    curl-7.42.1-2.42.1
Comment 17 Swamp Workflow Management 2015-05-28 14:05:42 UTC
SUSE-SU-2015:0962-1: An update that solves three vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 927174,927556,927746,928533
CVE References: CVE-2015-3143,CVE-2015-3148,CVE-2015-3153
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    curl-7.19.7-1.42.1
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    curl-7.19.7-1.42.1
SUSE Linux Enterprise Server 11 SP3 (src):    curl-7.19.7-1.42.1
SUSE Linux Enterprise Desktop 11 SP3 (src):    curl-7.19.7-1.42.1
Comment 18 Swamp Workflow Management 2015-06-03 07:05:53 UTC
SUSE-SU-2015:0990-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 927556,927607,927608,927746,928533
CVE References: CVE-2015-3143,CVE-2015-3144,CVE-2015-3145,CVE-2015-3148,CVE-2015-3153
Sources used:
SUSE Linux Enterprise Software Development Kit 12 (src):    curl-7.37.0-15.1
SUSE Linux Enterprise Server 12 (src):    curl-7.37.0-15.1
SUSE Linux Enterprise Desktop 12 (src):    curl-7.37.0-15.1
Comment 19 Andreas Stieger 2015-06-12 13:28:08 UTC
I see this as released everywhere.