Vulnerability Bulletins

DSA-4007 curl - security update

   
Affected software Debian
 
Brian Carpenter, Geeknik Labs and 0xd34db347 discovered that cURL, an URLtransfer library, incorrectly parsed an IMAP FETCH response with size 0,leading to an out-of-bounds read.

More info:

https://www.debian.org/security/2017/dsa-4007