USN-484-1: curl vulnerability

17 July 2007

curl vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 7.04
  • Ubuntu 6.10
  • Ubuntu 6.06 LTS

Software Description


It was discovered that the GnuTLS certificate verification methods implemented in Curl did not check for expiration and activation dates. When performing validations, tools using libcurl3-gnutls would incorrectly allow connections to sites using expired certificates.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 7.04
libcurl3-gnutls - 7.15.5-1ubuntu2.1
Ubuntu 6.10
libcurl3-gnutls - 7.15.4-1ubuntu2.2
Ubuntu 6.06 LTS
libcurl3-gnutls - 7.15.1-1ubuntu2.1

To update your system, please follow these instructions:

After a standard system upgrade you need to reboot your computer to effect the necessary changes.