-
Tue Dec 12 2023 Kevin Lyons <kevin.x.lyons@oracle.com> - 7.29.0-59.0.3.el7_9.2
- load CA certificates even with --insecure [Orabug: 32836997]
- Fix TFTP small blocksize heap buffer overflow (https://curl.haxx.se/docs/CVE-2019-5482.html)[CVE-2019-5482][Orabug: 30568724]
- Security Fixes [OraBug: 28939992]
- CVE-2016-8615 cookie injection for other servers (https://curl.haxx.se/docs/CVE-2016-8615.html)
- CVE-2016-8616 case insensitive password comparison (https://curl.haxx.se/docs/CVE-2016-8616.html)
- CVE-2016-8617 OOB write via unchecked multiplication (https://curl.haxx.se/docs/CVE-2016-8617.html)
- CVE-2016-8618 double-free in curl_maprintf (https://curl.haxx.se/docs/CVE-2016-8618.html)
- CVE-2016-8619 double-free in krb5 code (https://curl.haxx.se/docs/CVE-2016-8619.html)
- CVE-2016-8621 curl_getdate read out of bounds (https://curl.haxx.se/docs/CVE-2016-8621.html)
- CVE-2016-8622 URL unescape heap overflow via integer truncation (https://curl.haxx.se/docs/CVE-2016-8622.html)
- CVE-2016-8623 Use-after-free via shared cookies (https://curl.haxx.se/docs/CVE-2016-8623.html)
- CVE-2016-8624 invalid URL parsing with # (https://curl.haxx.se/docs/CVE-2016-8624.html)
- Drop 1001-tftp-Alloc-maximum-blksize-and-use-default-unless-OA.patch
-
Tue Nov 07 2023 Jacek Migacz <jmigacz@redhat.com> - 7.29.0-59.el7_9.2
- fix HTTP proxy deny use after free (CVE-2022-43552)
- rebuild certs with 2048-bit RSA keys
-
Tue Jul 28 2020 Kamil Dudka <kdudka@redhat.com> - 7.29.0-59.el7_9.1
- avoid overwriting a local file with -J (CVE-2020-8177)
-
Tue Jun 02 2020 Kamil Dudka <kdudka@redhat.com> - 7.29.0-59
- http: free protocol-specific struct in setup_connection callback (#1836773)
-
Mon Mar 23 2020 Kamil Dudka <kdudka@redhat.com> - 7.29.0-58
- fix heap buffer overflow in function tftp_receive_packet() (CVE-2019-5482)
-
Wed Nov 27 2019 Kamil Dudka <kdudka@redhat.com> - 7.29.0-57
- allow curl to POST from a char device (#1769307)
-
Tue Oct 01 2019 Kamil Dudka <kdudka@redhat.com> - 7.29.0-56
- fix auth failure with duplicated WWW-Authenticate header (#1754736)
-
Tue Aug 06 2019 Kamil Dudka <kdudka@redhat.com> - 7.29.0-55
- fix TFTP receive buffer overflow (CVE-2019-5436)
-
Mon Jun 03 2019 Kamil Dudka <kdudka@redhat.com> - 7.29.0-54
- make `curl --tlsv1` backward compatible (#1672639)
-
Mon May 27 2019 Kamil Dudka <kdudka@redhat.com> - 7.29.0-53
- backport the --tls-max option of curl and TLS 1.3 ciphers (#1672639)