Fedora 22 Security Update: curl-7.40.0-5.fc22

Resolved Bugs
1195771 – support “–pinnedpubkey” option (feature REQ)
1228363 – curl-config broken when i686 version installed on x86_64
1233818 – CVE-2015-3237 CVE-2015-3236 curl: various flaws [fedora-all]
1233814 – CVE-2015-3237 curl: SMB send off unrelated memory contents
1233816 – CVE-2015-3236 curl: lingering HTTP credentials in connection re-use<br
– implement public key pinning for NSS backend (#1195771)
– fix lingering HTTP credentials in connection re-use (CVE-2015-3236)
– prevent SMB from sending off unrelated memory contents (CVE-2015-3237)
– curl-config –libs now works on x86_64 without libcurl-devel.x86_64 (#1228363)

Leave a Reply