Multiple CVEs were reported in curl: cookie injection for other servers CVE-2016-8615 case insensitive password comparison CVE-2016-8616 OOB write via unchecked multiplication CVE-2016-8617 double-free in curl_maprintf CVE-2016-8618 double-free in krb5 code CVE-2016-8619 glob parser write/read out of bounds CVE-2016-8620 curl_getdate read out of bounds CVE-2016-8621 URL unescape heap overflow via integer truncation CVE-2016-8622 Use-after-free via shared cookies CVE-2016-8623 invalid URL parsing with '#' CVE-2016-8624 IDNA 2003 makes curl use wrong host CVE-2016-8625 For more info see https://curl.haxx.se/docs/security.html All branches seems to be affected.
Patch sent to master: https://patchwork.openembedded.org/patch/133682/ I will send patches to morty & krogoth soon.
curl 7.51.0-r0 address all these CVEs. A patch for master has been sent to upgrade curl to 7.51.0-r0. I wonder if we can upgrade krogoth and morty to 7.51.0-r0 as well? Both package versions are using same libcurl.so version i.e. libcurl.so.4.4.0: tmp/work/i586-poky-linux/curl/7.47.1-r0/sysroot-destdir/usr/lib/libcurl.so.4.4.0 tmp/work/i586-poky-linux/curl/7.51.0-r0/sysroot-destdir/usr/lib/libcurl.so.4.4.0
Patch sent to master is applicable for morty branch as well. Patches sent for krogoth.
in krogoth.
http://cgit.openembedded.org/openembedded-core/commit/?h=krogoth&id=bf8d4e9c8a7fed4e190d600a6a26d314d4b15a08 '' http://cgit.openembedded.org/openembedded-core/commit/?h=krogoth&id=ba4e218d1e09aaecbdb760a299826c03202a9ba9
http://git.yoctoproject.org/cgit.cgi/poky/commit/?h=morty&id=6131edc2c9de3d2fe03243a423e2441a6ec855ce and preceeding commits, so all maintained stable branches are fixed.