SUSE-SU-2025:20029-1
Advisory lineage Upstream: 6 Downstream: 0
Published: 03 Feb 2025, 08:51
Last modified:23 Mar 2026, 04:50
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
03 Feb 2025, 08:51
Published
Vulnerability first disclosed
23 Mar 2026, 04:50
Last Modified
Vulnerability information updated
Description
Security update for curl This update for curl fixes the following issues: Security issues fixed: - CVE-2024-7264: ASN.1 date parser overread (bsc#1228535) - CVE-2024-6197: Freeing stack buffer in utf8asn1str (bsc#1227888) - CVE-2024-2379: QUIC certificate check bypass with wolfSSL (bsc#1221666) - CVE-2024-2466: TLS certificate check bypass with mbedTLS (bsc#1221668) - CVE-2024-2004: Usage of disabled protocol (bsc#1221665) - CVE-2024-2398: HTTP/2 push headers memory-leak (bsc#1221667) Non-security issue fixed: - Fixed various TLS related issues including FTP over SSL transmission timeouts.
Affected Systems
- suse•curl&distro=SUSE Linux Micro 6.0
< 8.6.0-3.1
References (13)
- https://www.suse.com/support/update/announcement/2025/suse-su-202520029-1/
- https://bugzilla.suse.com/1221665
- https://bugzilla.suse.com/1221666
- https://bugzilla.suse.com/1221667
- https://bugzilla.suse.com/1221668
- https://bugzilla.suse.com/1227888
- https://bugzilla.suse.com/1228535
- https://www.suse.com/security/cve/CVE-2024-2004
- https://www.suse.com/security/cve/CVE-2024-2379
- https://www.suse.com/security/cve/CVE-2024-2398
- https://www.suse.com/security/cve/CVE-2024-2466
- https://www.suse.com/security/cve/CVE-2024-6197
- https://www.suse.com/security/cve/CVE-2024-7264