Bug 31704

Summary: curl new security issues CVE-2023-2753[3-8]
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Mageia Bug Squad <bugsquad>
Status: RESOLVED DUPLICATE QA Contact: Sec team <security>
Severity: major    
Priority: Normal    
Version: Cauldron   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: MGA8TOO
Source RPM: curl-7.88.1-1.mga9.src.rpm CVE:
Status comment: Fixed upstream in 8.0.1

Description David Walser 2023-03-20 17:50:31 CET
cURL has issued advisories today (March 20):
https://curl.se/docs/CVE-2023-27533.html
https://curl.se/docs/CVE-2023-27534.html
https://curl.se/docs/CVE-2023-27535.html
https://curl.se/docs/CVE-2023-27536.html
https://curl.se/docs/CVE-2023-27537.html
https://curl.se/docs/CVE-2023-27538.html

The issues are fixed upstream in 8.0.1:
https://curl.se/changes.html

Mageia 8 is affected by everything except CVE-2023-27537.
David Walser 2023-03-20 17:51:09 CET

Whiteboard: (none) => MGA8TOO
Status comment: (none) => Fixed upstream in 8.0.1

Comment 1 David Walser 2023-03-20 17:57:19 CET
Dup

*** This bug has been marked as a duplicate of bug 31703 ***

Status: NEW => RESOLVED
Resolution: (none) => DUPLICATE