[CLSA-2021:1634922432] Fix of CVE: CVE-2021-22876
Type:
security
Severity:
moderate
Release date:
2021-10-22
Description:
- back-port urlapi from v7.75.0 (used by CVE-2021-22876) - strip credentials from the auto-referer header (CVE-2021-22876)
Updated packages:
  • libcurl-devel-7.19.7-56.el6.cloudlinux.ol.els6.x86_64.rpm
    sha:876f81258d6031abb9b5714e7d90f290ab5abe75
  • libcurl-devel-7.19.7-56.el6.cloudlinux.ol.els6.i686.rpm
    sha:2a236d3df679f5f1ae8739d8e7decee1ef933bf5
  • curl-7.19.7-56.el6.cloudlinux.ol.els6.x86_64.rpm
    sha:e6d649bcf49f3508ff230d914ad095846d443dbc
  • libcurl-7.19.7-56.el6.cloudlinux.ol.els6.i686.rpm
    sha:81d35e6a607ac2fda5db6853472e4592c9a20018
  • libcurl-7.19.7-56.el6.cloudlinux.ol.els6.x86_64.rpm
    sha:4cd72ff344a558d40e1c62c5883bf04290b521ca
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.