UbuntuUpdates.org

Package "curl"

Name: curl

Description:

command line tool for transferring data with URL syntax

Latest version: 7.68.0-1ubuntu2.7
Release: focal (20.04)
Level: updates
Repository: main
Homepage: http://curl.haxx.se

Links


Download "curl"


Other versions of "curl" in Focal

Repository Area Version
base main 7.68.0-1ubuntu2
security main 7.68.0-1ubuntu2.7

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 7.68.0-1ubuntu2.1 2020-06-24 14:07:25 UTC

  curl (7.68.0-1ubuntu2.1) focal-security; urgency=medium

  * SECURITY UPDATE: Partial password leak over DNS on HTTP redirect
    - debian/patches/CVE-2020-8169.patch: make the updated credentials
      URL-encoded in the URL in lib/url.c, tests/data/test1168,
      tests/data/Makefile.inc.
    - CVE-2020-8169
  * SECURITY UPDATE: curl overwrite local file with -J
    - debian/patches/CVE-2020-8177.patch: -i is not OK if -J is used in
      src/tool_cb_hdr.c, src/tool_getparam.c.
    - CVE-2020-8177

 -- Marc Deslauriers <email address hidden> Wed, 17 Jun 2020 09:03:28 -0400




About   -   Send Feedback to @ubuntu_updates