Amazon Linux 1 Security Advisory: ALAS-2017-922
Advisory Release Date: 2017-11-15 19:54 Pacific
Advisory Updated Date: 2017-11-20 21:37 Pacific
IMAP FETCH response out of bounds read:
A buffer overrun flaw was found in the IMAP handler of libcurl. By tricking an unsuspecting user into connecting to a malicious IMAP server, an attacker could exploit this flaw to potentially cause information disclosure or crash the application. (CVE-2017-1000257)
Affected Packages:
curl
Issue Correction:
Run yum update curl to update your system.
i686:
curl-debuginfo-7.53.1-12.79.amzn1.i686
curl-7.53.1-12.79.amzn1.i686
libcurl-devel-7.53.1-12.79.amzn1.i686
libcurl-7.53.1-12.79.amzn1.i686
src:
curl-7.53.1-12.79.amzn1.src
x86_64:
curl-debuginfo-7.53.1-12.79.amzn1.x86_64
libcurl-devel-7.53.1-12.79.amzn1.x86_64
libcurl-7.53.1-12.79.amzn1.x86_64
curl-7.53.1-12.79.amzn1.x86_64