Recently I got a seurity advisory for the bff-package oss.lib.libcurl (https://www.ibm.com/support/pages/node/7095021?myns=swgother&mynp=OCSWG10&mync=E&cm_sp=swgother-_-OCSWG10-_-E) included in AIX 7.3.1 and 7.3.2.
We do not use this package, but the affected versions were given as 7.79.1.0-8.1.2.0 and the latest rpm-package is exactly 8.1.2-1 (curl-8.1.2-1.aix7.1.ppc.rpm) from Aug 11th. So I have two questions:
- Is this rpm-package vulnerable to the same exploit as the bff-package? The version number suggests so.
- If the package indeed is vulnerable are there any plans to provide a fixed update anytime soon?
Thanks for your consideration and kind regards
------------------------------
Wolf Machowitsch
------------------------------
#AIXOpenSource