Vulnerability Bulletins

DSA-4202 curl - security update

   
Affected software Debian
 
OSS-fuzz, assisted by Max Dymond, discovered that cURL, an URL transferlibrary, could be tricked into reading data beyond the end of a heapbased buffer when parsing invalid headers in an RTSP response.

More info:

https://www.debian.org/security/2018/dsa-4202