Subj : Curl library security flaws revealed To : All From : TechnologyDaily Date : Tue Oct 10 2023 14:45:04 Curl library security flaws revealed Date: Tue, 10 Oct 2023 13:31:23 +0000 Description: Two Curl security flaws identified, one of high severity - but a patch is still not here yet. FULL STORY ====================================================================== The Curl library is vulnerable to two flaws, one of which is arguably the most critical security flaw identified in curl in recent history, experts have warned. For the uninitiated, Curl is an open source command-line tool used to transfer data with URL syntax. It supports multiple network protocols, including SSL, TLS, HTTP, FTP, SMTP, and more. It is mostly used by developers and system administrators prevalently to interact with APIs, download files, and create automated workflows. Withholding details Saeed Abbasi, Product Manager with Qualys Threat Research Unit, published a blog post explaining the flaws and the upcoming fix. In the announcement, he said that the two vulnerabilities being addressed are tracked as CVE-2023-38545 and CVE-2023-38546. The first one is labeled as high-severity, and affects both libcurl and the curl tool. The second one is low-severity, and only impacts libcurl. Given that the fix is yet to be released, the researchers did not want to share any more details. Among other things, they couldnt say which versions were vulnerable, as that would help pinpoint the problematic areas quite accurately. In a GitHub discussion , maintainer Daniel Stenberg only said that the flaws affect "last several years" of versions. Thats as specific as I can get he said. "Sure, there is a minuscule risk that someone can find this (again) before we ship the patch, but this issue has stayed undetected for years for a reason," Stenberg added. The update is expected to be released on October 11 this year, when Curl will hit version 8.4.9, Abbasi confirmed. "Organizations should urgently inventory and scan all systems utilizing curl and libcurl, anticipating identifying potentially vulnerable versions once details are disclosed with the release of Curl 8.4.0 on October 11." More from TechRadar Pro One of the most popular WordPress plugins has a serious security flaw Here's a list of the best firewalls today These are the best malware removal tools right now ====================================================================== Link to news story: https://www.techradar.com/pro/security/curl-library-security-flaws-revealed --- Mystic BBS v1.12 A47 (Linux/64) * Origin: tqwNet Technology News (1337:1/100) .