此内容没有您所选择的语言版本。

Chapter 3. Security Fixes


This update includes fixes for the following security related issues:

Expand
IDImpactSummary

CVE-2016-0718

Moderate

expat: Out-of-bounds heap read on crafted input causing crash

CVE-2016-7167

Low

curl: escape and unescape integer overflows

CVE-2016-8615

Moderate

curl: Cookie injection for other servers

CVE-2016-8616

Low

curl: Case insensitive password comparison

CVE-2016-8617

Moderate

curl: Out-of-bounds write via unchecked multiplication

CVE-2016-8618

Moderate

curl: Double-free in curl_maprintf

CVE-2016-8619

Moderate

curl: Double-free in krb5 code

CVE-2016-8621

Low

curl: curl_getdate out-of-bounds read

CVE-2016-8622

Low

curl: URL unescape heap overflow via integer truncation

CVE-2016-8623

Low

curl: Use-after-free via shared cookies

CVE-2016-8624

Moderate

curl: Invalid URL parsing with '#'

CVE-2016-8625

Moderate

curl: IDNA 2003 makes curl use wrong host

CVE-2016-9598

Moderate

libxml2: out-of-bounds read (unfixed CVE-2016-4483 in JBCS)

CVE-2017-6004

Moderate

pcre: Out-of-bounds read in compile_bracket_matchingpath function (8.41/3)

CVE-2017-7186

Moderate

pcre: Invalid Unicode property lookup (8.41/7, 10.24/2)

CVE-2017-7244

Low

pcre: invalid memory read in _pcre32_xclass (pcre_xclass.c)

CVE-2017-7245

Low

pcre: stack-based buffer overflow write in pcre32_copy_substring

CVE-2017-7246

Low

pcre: stack-based buffer overflow write in pcre32_copy_substring

CVE-2017-1000254

Moderate

curl: FTP PWD response parser out of bounds read

CVE-2017-1000257

Moderate

curl: IMAP FETCH response out of bounds read

CVE-2018-0500

Moderate

curl: Heap-based buffer overflow in Curl_smtp_escape_eob() when uploading data over SMTP

返回顶部
Red Hat logoGithubredditYoutubeTwitter

学习

尝试、购买和销售

社区

关于红帽文档

通过我们的产品和服务,以及可以信赖的内容,帮助红帽用户创新并实现他们的目标。 了解我们当前的更新.

让开源更具包容性

红帽致力于替换我们的代码、文档和 Web 属性中存在问题的语言。欲了解更多详情,请参阅红帽博客.

關於紅帽

我们提供强化的解决方案,使企业能够更轻松地跨平台和环境(从核心数据中心到网络边缘)工作。

Theme

© 2025 Red Hat