Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2021:1027 - Security Advisory
Issued:
2021-03-30
Updated:
2021-03-30

RHSA-2021:1027 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: curl security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for curl is now available for Red Hat Enterprise Linux 7.7 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The curl packages provide the libcurl library and the curl utility for downloading files from servers using various protocols, including HTTP, FTP, and LDAP.

Security Fix(es):

  • curl: heap buffer overflow in function tftp_receive_packet() (CVE-2019-5482)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 7.7 x86_64
  • Red Hat Enterprise Linux Server - AUS 7.7 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 7.7 s390x
  • Red Hat Enterprise Linux for Power, big endian - Extended Update Support 7.7 ppc64
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 7.7 ppc64le
  • Red Hat Enterprise Linux Server - TUS 7.7 x86_64
  • Red Hat Enterprise Linux EUS Compute Node 7.7 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 7.7 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 7.7 x86_64

Fixes

  • BZ - 1749652 - CVE-2019-5482 curl: heap buffer overflow in function tftp_receive_packet()

CVEs

  • CVE-2019-5482

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 7.7

SRPM
curl-7.29.0-54.el7_7.4.src.rpm SHA-256: dea662ceb724588512239e569c1bd381b450168b8b01806982b963d1f7d2523f
x86_64
curl-7.29.0-54.el7_7.4.x86_64.rpm SHA-256: 037f1e5c9332a2872c9fc843458a03ee96f59566ba2e7a0930fd807f5d4764f3
curl-debuginfo-7.29.0-54.el7_7.4.i686.rpm SHA-256: c882d1e8bfc58a56915bea78cf1d0b597a76eae17f1d4e584edf9d02c46144a8
curl-debuginfo-7.29.0-54.el7_7.4.x86_64.rpm SHA-256: ab19bb1ebb1ea04f76f78895c986e816666a6d041d3e971f4621c80484003df8
libcurl-7.29.0-54.el7_7.4.i686.rpm SHA-256: 4205fd24fbcd36e82add26fe8e3988cc99345cb8514aa4ebc9cb4e41f55a6265
libcurl-7.29.0-54.el7_7.4.x86_64.rpm SHA-256: db90ba413ff1bef9b0b8536c2038b1590d9fefddce8a52759a32f5a239c35a4b
libcurl-devel-7.29.0-54.el7_7.4.i686.rpm SHA-256: b20f3b64318618cad7bfd269080b45fcab914cb454077f1fff6d17de119eb682
libcurl-devel-7.29.0-54.el7_7.4.x86_64.rpm SHA-256: 3497bc71fea373bba940b36ded9e590900ec88e7ba4b05073202b0e93d3103ad

Red Hat Enterprise Linux Server - AUS 7.7

SRPM
curl-7.29.0-54.el7_7.4.src.rpm SHA-256: dea662ceb724588512239e569c1bd381b450168b8b01806982b963d1f7d2523f
x86_64
curl-7.29.0-54.el7_7.4.x86_64.rpm SHA-256: 037f1e5c9332a2872c9fc843458a03ee96f59566ba2e7a0930fd807f5d4764f3
curl-debuginfo-7.29.0-54.el7_7.4.i686.rpm SHA-256: c882d1e8bfc58a56915bea78cf1d0b597a76eae17f1d4e584edf9d02c46144a8
curl-debuginfo-7.29.0-54.el7_7.4.x86_64.rpm SHA-256: ab19bb1ebb1ea04f76f78895c986e816666a6d041d3e971f4621c80484003df8
libcurl-7.29.0-54.el7_7.4.i686.rpm SHA-256: 4205fd24fbcd36e82add26fe8e3988cc99345cb8514aa4ebc9cb4e41f55a6265
libcurl-7.29.0-54.el7_7.4.x86_64.rpm SHA-256: db90ba413ff1bef9b0b8536c2038b1590d9fefddce8a52759a32f5a239c35a4b
libcurl-devel-7.29.0-54.el7_7.4.i686.rpm SHA-256: b20f3b64318618cad7bfd269080b45fcab914cb454077f1fff6d17de119eb682
libcurl-devel-7.29.0-54.el7_7.4.x86_64.rpm SHA-256: 3497bc71fea373bba940b36ded9e590900ec88e7ba4b05073202b0e93d3103ad

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 7.7

SRPM
curl-7.29.0-54.el7_7.4.src.rpm SHA-256: dea662ceb724588512239e569c1bd381b450168b8b01806982b963d1f7d2523f
s390x
curl-7.29.0-54.el7_7.4.s390x.rpm SHA-256: ed70ca4a51003cdf6aacfd89eee613ce6f7447ae247d92255ad0bc397805dc32
curl-debuginfo-7.29.0-54.el7_7.4.s390.rpm SHA-256: e556cac84014949cbddcce50ea52393465335086e9f24e3ac0f0bba981838fb9
curl-debuginfo-7.29.0-54.el7_7.4.s390x.rpm SHA-256: 77a9a3da453f0ef8dcd0837cdeeb0ba629910557de5765165380db40d840bba1
libcurl-7.29.0-54.el7_7.4.s390.rpm SHA-256: 72e192a42892a42e2aae47e52a6c30958253ba1b05994562e6683a47568c4dcf
libcurl-7.29.0-54.el7_7.4.s390x.rpm SHA-256: e934a8f1a5f4e026e9f23d9c0b3db4c60b509f693499c8ad64912e0952d8e687
libcurl-devel-7.29.0-54.el7_7.4.s390.rpm SHA-256: 8a20d30db08e0f645555000960afd06f234732d66ed7b42dca1c58b7e8c49b52
libcurl-devel-7.29.0-54.el7_7.4.s390x.rpm SHA-256: 3b3eee981f0c8ef50217fc4b17a96aa4bc2a47fbde6a158423757f890494b305

Red Hat Enterprise Linux for Power, big endian - Extended Update Support 7.7

SRPM
curl-7.29.0-54.el7_7.4.src.rpm SHA-256: dea662ceb724588512239e569c1bd381b450168b8b01806982b963d1f7d2523f
ppc64
curl-7.29.0-54.el7_7.4.ppc64.rpm SHA-256: 4f98248c6d3a8341e7d53ef84aa177e432c257ad14fef4283a57d8172f1fc466
curl-debuginfo-7.29.0-54.el7_7.4.ppc.rpm SHA-256: ea17575c7ca79f87272c2031f0afd8cbd001e99a21b2310f1d500028e48bba97
curl-debuginfo-7.29.0-54.el7_7.4.ppc64.rpm SHA-256: 694608a36a11d76a39a01a64d015654fb1a874308afccb62758ad211c7335239
libcurl-7.29.0-54.el7_7.4.ppc.rpm SHA-256: f0c40d188f4e83d0520d6ac3d4115afd3144c4051b9eeba994c442487af9302f
libcurl-7.29.0-54.el7_7.4.ppc64.rpm SHA-256: 6f7cd1c2263d961c4266710e1cee4cb0b8a62ac6e6f7b7054e22094236803a86
libcurl-devel-7.29.0-54.el7_7.4.ppc.rpm SHA-256: 6438a70204e4aa5bb7707d481f69ecd53482dec332dbbd9f989622655a95d033
libcurl-devel-7.29.0-54.el7_7.4.ppc64.rpm SHA-256: 7d7a24beac9e240446d8e66d927b5e1d1da437393b48b80ae20ad89a1fef3fb7

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 7.7

SRPM
curl-7.29.0-54.el7_7.4.src.rpm SHA-256: dea662ceb724588512239e569c1bd381b450168b8b01806982b963d1f7d2523f
ppc64le
curl-7.29.0-54.el7_7.4.ppc64le.rpm SHA-256: 8258e3a7857eb30ff80d4628c5e049e591b6311b4e312c8a024bc668eec5e6a1
curl-debuginfo-7.29.0-54.el7_7.4.ppc64le.rpm SHA-256: ae5739e02d1404e24e5754efc324ce92638f4acb37200855d823c15afa73d723
libcurl-7.29.0-54.el7_7.4.ppc64le.rpm SHA-256: 3fa3f11c531a8a8040d28bde87ab8d874245f12556bfa468aedfb52655fd23f4
libcurl-devel-7.29.0-54.el7_7.4.ppc64le.rpm SHA-256: 85131a83478b2b3e0ac02b22fa41c078bcd4b1a29c8f4273ae3fb6a976fb574d

Red Hat Enterprise Linux Server - TUS 7.7

SRPM
curl-7.29.0-54.el7_7.4.src.rpm SHA-256: dea662ceb724588512239e569c1bd381b450168b8b01806982b963d1f7d2523f
x86_64
curl-7.29.0-54.el7_7.4.x86_64.rpm SHA-256: 037f1e5c9332a2872c9fc843458a03ee96f59566ba2e7a0930fd807f5d4764f3
curl-debuginfo-7.29.0-54.el7_7.4.i686.rpm SHA-256: c882d1e8bfc58a56915bea78cf1d0b597a76eae17f1d4e584edf9d02c46144a8
curl-debuginfo-7.29.0-54.el7_7.4.x86_64.rpm SHA-256: ab19bb1ebb1ea04f76f78895c986e816666a6d041d3e971f4621c80484003df8
libcurl-7.29.0-54.el7_7.4.i686.rpm SHA-256: 4205fd24fbcd36e82add26fe8e3988cc99345cb8514aa4ebc9cb4e41f55a6265
libcurl-7.29.0-54.el7_7.4.x86_64.rpm SHA-256: db90ba413ff1bef9b0b8536c2038b1590d9fefddce8a52759a32f5a239c35a4b
libcurl-devel-7.29.0-54.el7_7.4.i686.rpm SHA-256: b20f3b64318618cad7bfd269080b45fcab914cb454077f1fff6d17de119eb682
libcurl-devel-7.29.0-54.el7_7.4.x86_64.rpm SHA-256: 3497bc71fea373bba940b36ded9e590900ec88e7ba4b05073202b0e93d3103ad

Red Hat Enterprise Linux EUS Compute Node 7.7

SRPM
curl-7.29.0-54.el7_7.4.src.rpm SHA-256: dea662ceb724588512239e569c1bd381b450168b8b01806982b963d1f7d2523f
x86_64
curl-7.29.0-54.el7_7.4.x86_64.rpm SHA-256: 037f1e5c9332a2872c9fc843458a03ee96f59566ba2e7a0930fd807f5d4764f3
curl-debuginfo-7.29.0-54.el7_7.4.i686.rpm SHA-256: c882d1e8bfc58a56915bea78cf1d0b597a76eae17f1d4e584edf9d02c46144a8
curl-debuginfo-7.29.0-54.el7_7.4.i686.rpm SHA-256: c882d1e8bfc58a56915bea78cf1d0b597a76eae17f1d4e584edf9d02c46144a8
curl-debuginfo-7.29.0-54.el7_7.4.x86_64.rpm SHA-256: ab19bb1ebb1ea04f76f78895c986e816666a6d041d3e971f4621c80484003df8
curl-debuginfo-7.29.0-54.el7_7.4.x86_64.rpm SHA-256: ab19bb1ebb1ea04f76f78895c986e816666a6d041d3e971f4621c80484003df8
libcurl-7.29.0-54.el7_7.4.i686.rpm SHA-256: 4205fd24fbcd36e82add26fe8e3988cc99345cb8514aa4ebc9cb4e41f55a6265
libcurl-7.29.0-54.el7_7.4.x86_64.rpm SHA-256: db90ba413ff1bef9b0b8536c2038b1590d9fefddce8a52759a32f5a239c35a4b
libcurl-devel-7.29.0-54.el7_7.4.i686.rpm SHA-256: b20f3b64318618cad7bfd269080b45fcab914cb454077f1fff6d17de119eb682
libcurl-devel-7.29.0-54.el7_7.4.x86_64.rpm SHA-256: 3497bc71fea373bba940b36ded9e590900ec88e7ba4b05073202b0e93d3103ad

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 7.7

SRPM
curl-7.29.0-54.el7_7.4.src.rpm SHA-256: dea662ceb724588512239e569c1bd381b450168b8b01806982b963d1f7d2523f
ppc64le
curl-7.29.0-54.el7_7.4.ppc64le.rpm SHA-256: 8258e3a7857eb30ff80d4628c5e049e591b6311b4e312c8a024bc668eec5e6a1
curl-debuginfo-7.29.0-54.el7_7.4.ppc64le.rpm SHA-256: ae5739e02d1404e24e5754efc324ce92638f4acb37200855d823c15afa73d723
libcurl-7.29.0-54.el7_7.4.ppc64le.rpm SHA-256: 3fa3f11c531a8a8040d28bde87ab8d874245f12556bfa468aedfb52655fd23f4
libcurl-devel-7.29.0-54.el7_7.4.ppc64le.rpm SHA-256: 85131a83478b2b3e0ac02b22fa41c078bcd4b1a29c8f4273ae3fb6a976fb574d

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 7.7

SRPM
curl-7.29.0-54.el7_7.4.src.rpm SHA-256: dea662ceb724588512239e569c1bd381b450168b8b01806982b963d1f7d2523f
x86_64
curl-7.29.0-54.el7_7.4.x86_64.rpm SHA-256: 037f1e5c9332a2872c9fc843458a03ee96f59566ba2e7a0930fd807f5d4764f3
curl-debuginfo-7.29.0-54.el7_7.4.i686.rpm SHA-256: c882d1e8bfc58a56915bea78cf1d0b597a76eae17f1d4e584edf9d02c46144a8
curl-debuginfo-7.29.0-54.el7_7.4.x86_64.rpm SHA-256: ab19bb1ebb1ea04f76f78895c986e816666a6d041d3e971f4621c80484003df8
libcurl-7.29.0-54.el7_7.4.i686.rpm SHA-256: 4205fd24fbcd36e82add26fe8e3988cc99345cb8514aa4ebc9cb4e41f55a6265
libcurl-7.29.0-54.el7_7.4.x86_64.rpm SHA-256: db90ba413ff1bef9b0b8536c2038b1590d9fefddce8a52759a32f5a239c35a4b
libcurl-devel-7.29.0-54.el7_7.4.i686.rpm SHA-256: b20f3b64318618cad7bfd269080b45fcab914cb454077f1fff6d17de119eb682
libcurl-devel-7.29.0-54.el7_7.4.x86_64.rpm SHA-256: 3497bc71fea373bba940b36ded9e590900ec88e7ba4b05073202b0e93d3103ad

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility