MDVA-2008:159 : curl

high Nessus Plugin ID 37782

Synopsis

The remote Mandriva host is missing one or more security-related patches.

Description

An idiosyncratic feature of the Turkish language is that the letter 'i' in Turkish is not the lower-case version of the letter 'I'. This issue breaks standard POSIX string case comparison on strings containing the character 'i'. This issue affected the curl package shipped with Mandriva Linux 2009, which ultimately caused it to be incapable of handling URIs of the form file:///somefile in Turkish locales. In turn, curl is used by webkit, which is used by the Mandriva Linux Control Center, ultimately resulting in the Control Center not rendering icons in its user interface when run in Turkish locales. The bug likely also has other implications for curl-based applications in Turkish locales.

The fixed package includes a fix for this issue, so that curl will correctly handle file:///somefile URIs in Turkish locales. As a consequence, the Mandriva Linux Control Center now properly renders icons in Turkish locales.

Solution

Update the affected package(s).

See Also

http://www.mandriva.com/security/advisories?name=MDVA-2008:159

Plugin Details

Severity: High

ID: 37782

File Name: mandriva_MDVA-2008-159.nasl

Version: 1.11

Type: local

Published: 4/23/2009

Updated: 1/6/2021

Supported Sensors: Nessus

Vulnerability Information

CPE: cpe:/o:mandriva:linux

Required KB Items: Host/Mandrake/release, Host/Mandrake/rpm-list

Patch Publication Date: 10/27/2008