Publishing details

Changelog

curl (7.88.1-11+20.04.sav1) focal; urgency=medium

  * SECURITY UPDATE: SOCKS5 heap buffer overflow
    - debian/patches/CVE-2023-38545.patch: return error if hostname too
      long for remote resolve in lib/socks.c, tests/data/Makefile.inc,
      tests/data/test728.
    - CVE-2023-38545
  * SECURITY UPDATE: cookie injection with none file
    - debian/patches/CVE-2023-38546.patch: remove unnecessary struct fields
      in lib/cookie.c, lib/cookie.h, lib/easy.c.
    - CVE-2023-38546
    [ patches thanks to Marc Deslauriers <email address hidden> ]

 -- Rob Savoury <email address hidden>  Fri, 20 Oct 2023 06:47:26 -0700

Available diffs

Builds

Built packages

Package files