Summary
The remote host is missing an update to curl
announced via advisory USN-818-1.
Solution
The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 6.06 LTS:
libcurl3 7.15.1-1ubuntu3.2
Ubuntu 8.04 LTS:
libcurl3 7.18.0-1ubuntu2.2
Ubuntu 8.10:
libcurl3 7.18.2-1ubuntu4.4
Ubuntu 9.04:
libcurl3 7.18.2-8ubuntu4.1
In general, a standard system upgrade is sufficient to effect the necessary changes.
https://secure1.securityspace.com/smysecure/catid.html?in=USN-818-1
Insight
Scott Cantor discovered that Curl did not correctly handle SSL certificates with zero bytes in the Common Name. A remote attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications.
Severity
Classification
-
CVE CVE-2009-2417 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities