Errata overview
Errata ID 299
Date 2018-11-07
Source package curl
Fixed in version 7.52.1-5+deb9u8
Description
This update addresses the following issues:
* Heap-based buffer overflow via integer overflow in
  curl_sasl.c:Curl_sasl_create_plain_message() (CVE-2018-16839)
* Heap-based buffer over-read in tool_msgs.c:voutf() allows for information
  disclosure and crash (CVE-2018-16842)
Additional notes
CVE ID CVE-2018-16839
CVE-2018-16842
UCS Bug number #48093