Amazon Linux 1 (EOL) Security Advisory: ALAS-2017-922
Advisory Released Date: 2017-11-15
Advisory Updated Date: 2017-11-20
Severity:
Medium
Issue Overview:
IMAP FETCH response out of bounds read:
A buffer overrun flaw was found in the IMAP handler of libcurl. By tricking an unsuspecting user into connecting to a malicious IMAP server, an attacker could exploit this flaw to potentially cause information disclosure or crash the application. (CVE-2017-1000257)
Affected Packages:
curl
Issue Correction:
Run yum update curl to update your system.
New Packages:
i686:
curl-debuginfo-7.53.1-12.79.amzn1.i686
curl-7.53.1-12.79.amzn1.i686
libcurl-devel-7.53.1-12.79.amzn1.i686
libcurl-7.53.1-12.79.amzn1.i686
src:
curl-7.53.1-12.79.amzn1.src
x86_64:
curl-debuginfo-7.53.1-12.79.amzn1.x86_64
libcurl-devel-7.53.1-12.79.amzn1.x86_64
libcurl-7.53.1-12.79.amzn1.x86_64
curl-7.53.1-12.79.amzn1.x86_64