• Severity HIGH security problem to be announced with curl 8.4.0 on Oct 11

    From rek2 hispagatos@rek2@hispagatos.org.invalid to alt.2600.madrid,alt.2600,alt.2600.hackers,es.comp.hackers on Thu Oct 5 15:13:01 2023
    From Newsgroup: alt.2600.hackers

    Severity HIGH security problem to be announced with curl 8.4.0 on Oct 11

    The new version and details about the two CVEs will be published
    around 06:00 UTC on the release day.

    CVE-2023-38545: severity HIGH (affects both libcurl and the curl tool)
    CVE-2023-38546: severity LOW (affects libcurl only, not the tool)

    There is no API nor ABI change in the coming curl release.

    For more info:
    https://github.com/curl/curl/discussions/12026

    Happy Hacking
    ReK2
    --
    - {gemini,https}://{,rek2.}hispagatos.org - mastodon: @rek2@hispagatos.space
    - [https|gemini]://2600.Madrid - https://hispagatos.space/@rek2
    - https://keyoxide.org/A31C7CE19D9C58084EA42BA26C0B0D11E9303EC5
    --- Synchronet 3.21d-Linux NewsLink 1.2