<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE2-SA-2024-0270</id>
    <title>An update for curl is now available for HCE 2.0</title>
    <severity>Moderate</severity>
    <release>HCE 2.0</release>
    <issued date="2024-11-19 07:40:47"/>
    <updated date="2024-11-19 07:40:47"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-8096" id="CVE-2024-8096" title="CVE-2024-8096 Base Score: 6.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" type="cve"/>
    </references>
    <description>Security Fix(es):

When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine.  If the returned status reports another error than _x27;revoked_x27; (like for example _x27;unauthorized_x27;) it is not treated as a bad certficate. (CVE-2024-8096)
</description>
    <pkglist>
      <collection short="HCE 2.0" package="curl">
        <name>HCE 2.0</name>
        <package arch="aarch64" name="curl" version="7.79.1" release="2.r31.hce2">
          <filename>curl-7.79.1-2.r31.hce2.aarch64.rpm</filename>
        </package>
        <package arch="noarch" name="curl-help" version="7.79.1" release="2.r31.hce2">
          <filename>curl-help-7.79.1-2.r31.hce2.noarch.rpm</filename>
        </package>
        <package arch="aarch64" name="libcurl" version="7.79.1" release="2.r31.hce2">
          <filename>libcurl-7.79.1-2.r31.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="libcurl-devel" version="7.79.1" release="2.r31.hce2">
          <filename>libcurl-devel-7.79.1-2.r31.hce2.aarch64.rpm</filename>
        </package>
        <package arch="x86_64" name="curl" version="7.79.1" release="2.r31.hce2">
          <filename>curl-7.79.1-2.r31.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="libcurl" version="7.79.1" release="2.r31.hce2">
          <filename>libcurl-7.79.1-2.r31.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="libcurl-devel" version="7.79.1" release="2.r31.hce2">
          <filename>libcurl-devel-7.79.1-2.r31.hce2.x86_64.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
