Amazon Linux AMI : curl (ALAS-2017-806)
Medium Nessus Plugin ID 97896
SynopsisThe remote Amazon Linux AMI host is missing a security update.
Descriptionlibcurl's implementation of the printf() functions triggers a buffer overflow when doing a large floating point output. If there are any application that accepts a format string from the outside without necessary input filtering, it could allow remote attacks. This flaw does not exist in the command line tool.
SolutionRun 'yum update curl' to update your system.