Source: curl
Version: 7.64.0-3
Severity: important
Tags: security upstream

Hi,

The following vulnerability was published for curl.

CVE-2019-5435[0]:
Integer overflows in curl_url_set

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2019-5435
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-5435
[1] https://www.openwall.com/lists/oss-security/2019/05/22/2
[2] https://curl.haxx.se/docs/CVE-2019-5435.html

Please adjust the affected versions in the BTS as needed, stretch is
afaict not affected but needs to check if we backported the
introducing commit.

Regards,
Salvatore

Reply via email to