UbuntuUpdates.org

Package "libcurl4t64"

Name: libcurl4t64

Description:

easy-to-use client-side URL transfer library (OpenSSL flavour)

Latest version: 8.9.1-2ubuntu2.1
Release: oracular (24.10)
Level: security
Repository: main
Head package: curl
Homepage: https://curl.se/

Links


Download "libcurl4t64"


Other versions of "libcurl4t64" in Oracular

Repository Area Version
base main 8.9.1-2ubuntu2
updates main 8.9.1-2ubuntu2.1

Changelog

Version: 8.9.1-2ubuntu2.1 2024-11-18 18:06:51 UTC

  curl (8.9.1-2ubuntu2.1) oracular-security; urgency=medium

  * SECURITY UPDATE: HSTS expiry overwrites parent cache entry.
    - debian/patches/CVE-2024-9681.patch: Add bestsub, blen, and hostname
      comparison in lib/hsts.c.
    - CVE-2024-9681

 -- Hlib Korzhynskyy <email address hidden> Wed, 06 Nov 2024 09:10:08 -0330

CVE-2024-9681 When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or later than oth



About   -   Send Feedback to @ubuntu_updates