<div dir="ltr"><div dir="ltr"><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Jun 15, 2022 at 11:47 PM Ruelo, Christine M. L. <<a href="mailto:christine.m.l.ruelo@accenture.com">christine.m.l.ruelo@accenture.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<div lang="EN-US" style="overflow-wrap: break-word;">
<div class="gmail-m_-8192746300748028313WordSection1">
<p class="MsoNormal">Hello libcurl4,curl <span style="color:black;background:white">
Maintainers,</span><span style="background:white"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="background:white"><u></u>Â <u></u></span></p>
<p class="MsoNormal"><span style="color:black;background:white">Good day, We have used the libcurl4,curl package and perform a security scan using Palo Alto Network – Prisma Cloud and these vulnerabilities below are reported.</span></p></div></div></blockquote><div><br></div><div>Hi,</div><div>not sure which Ubuntu releases you scanned but all these were handled and fixed quite a while ago.</div><div>To help you find that information yourself for this and any other cases let me point you to USN [1].</div><div><br></div><div>There you can enter your CVE numbers and will find which release was affected and in which package versions it got fixed.</div><div>If you want to do such checks automatically there is also oval data [2].</div><div><br></div><div>If your scanners still report the issue you'll need to check that in detail, but form my personal experience in 9 out of 10 cases the problem is that they only perform "if version > X" which doesn't always work well for fixes backported to versions that are in Distributions (for example libcurl3-gnutls - 7.74.0-1ubuntu2 becomes libcurl3-gnutls - 7.74.0-1ubuntu2.1 due to the fix - but the scanner might just check > 7.75).</div><div><br></div><div>[1]: <a href="https://ubuntu.com/security/notices">https://ubuntu.com/security/notices</a></div><div>[2]: <a href="https://ubuntu.com/security/oval">https://ubuntu.com/security/oval</a></div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div lang="EN-US" style="overflow-wrap: break-word;"><div class="gmail-m_-8192746300748028313WordSection1"><p class="MsoNormal"><span style="color:black;background:white">
</span><span style="background:white"><u></u><u></u></span></p>
<p class="MsoNormal"><span style="color:black;background:white">We would like to report it and let us know once the fix is available so we can update accordingly.
</span><span style="background:white"><u></u><u></u></span></p>
<p class="MsoNormal"><u></u>Â <u></u></p>
<table border="1" cellspacing="0" cellpadding="0" width="134" style="width:1.4in;border-collapse:collapse;border:none">
<tbody>
<tr style="height:15.75pt">
<td width="134" nowrap valign="bottom" style="width:1.4in;border:1pt solid windowtext;padding:0in 5.4pt;height:15.75pt">
<p class="MsoNormal"><span style="font-size:12pt">CVE-2021-22898<u></u><u></u></span></p>
</td>
</tr>
<tr style="height:15.75pt">
<td width="134" nowrap valign="bottom" style="width:1.4in;border-right:1pt solid windowtext;border-bottom:1pt solid windowtext;border-left:1pt solid windowtext;border-top:none;padding:0in 5.4pt;height:15.75pt">
<p class="MsoNormal"><span style="font-size:12pt">CVE-2021-22947<u></u><u></u></span></p>
</td>
</tr>
<tr style="height:15.75pt">
<td width="134" nowrap valign="bottom" style="width:1.4in;border-right:1pt solid windowtext;border-bottom:1pt solid windowtext;border-left:1pt solid windowtext;border-top:none;padding:0in 5.4pt;height:15.75pt">
<p class="MsoNormal"><span style="font-size:12pt">CVE-2021-22946<u></u><u></u></span></p>
</td>
</tr>
<tr style="height:15.75pt">
<td width="134" nowrap valign="bottom" style="width:1.4in;border-right:1pt solid windowtext;border-bottom:1pt solid windowtext;border-left:1pt solid windowtext;border-top:none;padding:0in 5.4pt;height:15.75pt">
<p class="MsoNormal"><span style="font-size:12pt">CVE-2021-22945<u></u><u></u></span></p>
</td>
</tr>
<tr style="height:15.75pt">
<td width="134" nowrap valign="bottom" style="width:1.4in;border-right:1pt solid windowtext;border-bottom:1pt solid windowtext;border-left:1pt solid windowtext;border-top:none;padding:0in 5.4pt;height:15.75pt">
<p class="MsoNormal"><span style="font-size:12pt">CVE-2021-22924<u></u><u></u></span></p>
</td>
</tr>
</tbody>
</table>
<p class="MsoNormal"><u></u>Â <u></u></p>
<p class="MsoNormal">Thank you<u></u><u></u></p>
<p class="MsoNormal"><u></u>Â <u></u></p>
<p class="MsoNormal">Regards,<u></u><u></u></p>
<p class="MsoNormal"><span style="font-size:10pt;font-family:Graphik,sans-serif"><img width="210" height="19" style="width: 2.1875in; height: 0.1979in;" id="gmail-m_-8192746300748028313Picture_x0020_1" src="cid:1817fc982eb4cff311"></span><b><span style="font-family:"Graphik Medium",sans-serif"><u></u><u></u></span></b></p>
<p class="MsoNormal"><b><span style="font-size:10pt;font-family:Graphik,sans-serif;color:rgb(161,0,255)">I</span></b><b><span style="font-size:10pt;font-family:Graphik,sans-serif;color:rgb(112,48,160)">
</span></b><span style="font-size:10pt;font-family:Graphik,sans-serif;color:black">CHRISTINE MAE RUELO<u></u><u></u></span></p>
<p class="MsoNormal"><b><span style="font-size:10pt;font-family:Graphik,sans-serif;color:rgb(161,0,255)">I</span></b><b><span style="font-size:10pt;font-family:Graphik,sans-serif;color:rgb(112,48,160)">
</span></b><span style="font-size:10pt;font-family:Graphik,sans-serif;color:black">ATCP | Data + AI<u></u><u></u></span></p>
<p class="MsoNormal"><b><span style="font-size:10pt;font-family:Graphik,sans-serif;color:rgb(161,0,255)">I</span></b><b><span style="font-size:10pt;font-family:Graphik,sans-serif;color:rgb(112,48,160)">
</span></b><span style="font-size:10pt;font-family:Graphik,sans-serif;color:black">Global One Eastwood<u></u><u></u></span></p>
<p class="MsoNormal"><b><span style="font-size:10pt;font-family:Graphik,sans-serif;color:rgb(161,0,255)">I</span></b><b><span style="font-size:10pt;font-family:Graphik,sans-serif;color:rgb(112,48,160)">
</span></b><span style="font-size:10pt;font-family:Graphik,sans-serif;color:black">E:
</span><a href="mailto:christine.m.l.ruelo@accenture.com" target="_blank"><span style="color:rgb(5,99,193)">christine.m.l.ruelo@accenture.com</span></a><u></u><u></u></p>
<p class="MsoNormal"><b><span style="font-size:10pt;font-family:Graphik,sans-serif;color:rgb(161,0,255)">I</span></b><b><span style="font-size:10pt;font-family:Graphik,sans-serif;color:rgb(112,48,160)">
</span></b><span style="font-size:10pt;font-family:Graphik,sans-serif;color:black">M: +63 927 088 6796<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:9pt;font-family:Graphik,sans-serif;color:rgb(89,89,89)">Accenture Confidential<u></u><u></u></span></p>
<p class="MsoNormal"><b><span style="font-size:8pt;font-family:Arial,sans-serif;color:red">PTO:
</span></b><span style="font-size:8pt;font-family:Arial,sans-serif;color:rgb(38,38,38)"><u></u><u></u></span></p>
<p class="MsoNormal"><b><span style="font-size:8pt;font-family:Arial,sans-serif;color:red">Holiday:
</span></b><span style="font-size:8pt;font-family:Arial,sans-serif;color:rgb(38,38,38)"><u></u><u></u></span></p>
<p class="MsoNormal"><b><span style="font-size:8pt;font-family:Arial,sans-serif;color:red">Training:
</span></b><span style="font-size:8pt;font-family:Arial,sans-serif;color:rgb(38,38,38)"><u></u><u></u></span></p>
<p class="MsoNormal"><u></u>Â <u></u></p>
</div>
<br>
<hr>
<font face="Arial" color="Gray" size="1"><br>
This message is for the designated recipient only and may contain privileged, proprietary, or otherwise confidential information. If you have received it in error, please notify the sender immediately and delete the original. Any other use of the e-mail by
you is prohibited. Where allowed by local law, electronic communications with Accenture and its affiliates, including e-mail and instant messaging (including content), may be scanned by our systems for the purposes of information security and assessment of
internal compliance with Accenture policy. Your privacy is important to us. Accenture uses your personal data only in compliance with data protection laws. For further information on how Accenture processes your personal data, please see our privacy statement
at <a href="https://www.accenture.com/us-en/privacy-policy" target="_blank">https://www.accenture.com/us-en/privacy-policy</a>. <br>
______________________________________________________________________________________<br>
<br>
<a href="http://www.accenture.com" target="_blank">www.accenture.com</a><br>
</font>
</div>
-- <br>
Ubuntu-devel-discuss mailing list<br>
<a href="mailto:Ubuntu-devel-discuss@lists.ubuntu.com" target="_blank">Ubuntu-devel-discuss@lists.ubuntu.com</a><br>
Modify settings or unsubscribe at: <a href="https://lists.ubuntu.com/mailman/listinfo/ubuntu-devel-discuss" rel="noreferrer" target="_blank">https://lists.ubuntu.com/mailman/listinfo/ubuntu-devel-discuss</a><br>
</blockquote></div><br clear="all"><div><br></div>-- <br><div dir="ltr" class="gmail_signature">Christian Ehrhardt<br>Staff Engineer, Ubuntu Server<br>Canonical Ltd</div></div>