oss-sec mailing list archives

Re: There is a curl "severity HIGH security problem" pre-announcement on GitHub


From: Shawn Webb <shawn.webb () hardenedbsd org>
Date: Thu, 5 Oct 2023 09:54:11 -0400

On Thu, Oct 05, 2023 at 10:14:49AM +0200, Erik Auerswald wrote:
Hi,

there is a pre-announcement of a curl security problem with high severity
that can be found on GitHub:

 - https://github.com/curl/curl/discussions
 - https://github.com/curl/curl/discussions/12026

I wonder if this could also be coordinated through CERT VINCE since
there will be a wider impact than those on the distros mailing list.

Thanks,

-- 
Shawn Webb
Cofounder / Security Engineer
HardenedBSD

https://git.hardenedbsd.org/hardenedbsd/pubkeys/-/raw/master/Shawn_Webb/03A4CBEBB82EA5A67D9F3853FF2E67A277F8E1FA.pub.asc

Attachment: signature.asc
Description:


Current thread: