ALAS-2017-922

Related Vulnerabilities: CVE-2017-1000257  

IMAP FETCH response out of bounds read:A buffer overrun flaw was found in the IMAP handler of libcurl. By tricking an unsuspecting user into connecting to a malicious IMAP server, an attacker could exploit this flaw to potentially cause information disclosure or crash the application. (CVE-2017-1000257)

ALAS-2017-922


Amazon Linux AMI Security Advisory: ALAS-2017-922
Advisory Release Date: 2017-11-15 19:54 Pacific
Advisory Updated Date: 2017-11-20 21:37 Pacific
Severity: Medium
References: CVE-2017-1000257 

Issue Overview:

IMAP FETCH response out of bounds read:
A buffer overrun flaw was found in the IMAP handler of libcurl. By tricking an unsuspecting user into connecting to a malicious IMAP server, an attacker could exploit this flaw to potentially cause information disclosure or crash the application. (CVE-2017-1000257)


Affected Packages:

curl


Issue Correction:
Run yum update curl to update your system.

New Packages:
i686:
    curl-debuginfo-7.53.1-12.79.amzn1.i686
    curl-7.53.1-12.79.amzn1.i686
    libcurl-devel-7.53.1-12.79.amzn1.i686
    libcurl-7.53.1-12.79.amzn1.i686

src:
    curl-7.53.1-12.79.amzn1.src

x86_64:
    curl-debuginfo-7.53.1-12.79.amzn1.x86_64
    libcurl-devel-7.53.1-12.79.amzn1.x86_64
    libcurl-7.53.1-12.79.amzn1.x86_64
    curl-7.53.1-12.79.amzn1.x86_64