UbuntuUpdates.org

Package "curl"

Name: curl

Description:

command line tool for transferring data with URL syntax

Latest version: 8.9.1-2ubuntu2.1
Release: oracular (24.10)
Level: updates
Repository: main
Homepage: https://curl.se/

Links


Download "curl"


Other versions of "curl" in Oracular

Repository Area Version
base main 8.9.1-2ubuntu2
security main 8.9.1-2ubuntu2.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 8.9.1-2ubuntu2.1 2024-11-18 19:07:21 UTC

  curl (8.9.1-2ubuntu2.1) oracular-security; urgency=medium

  * SECURITY UPDATE: HSTS expiry overwrites parent cache entry.
    - debian/patches/CVE-2024-9681.patch: Add bestsub, blen, and hostname
      comparison in lib/hsts.c.
    - CVE-2024-9681

 -- Hlib Korzhynskyy <email address hidden> Wed, 06 Nov 2024 09:10:08 -0330

CVE-2024-9681 When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or later than oth



About   -   Send Feedback to @ubuntu_updates