|
|
Log in / Subscribe / Register

Mageia alert MGASA-2024-0391 (curl)

From:  Mageia Updates <updates-announce@ml.mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2024-0391: Updated curl packages fix security vulnerability
Date:  Tue, 17 Dec 2024 20:43:02 +0100
Message-ID:  <20241217194302.2223CA0DB2@duvel.mageia.org>
Archive-link:  Article

MGASA-2024-0391 - Updated curl packages fix security vulnerability Publication date: 17 Dec 2024 URL: https://advisories.mageia.org/MGASA-2024-0391.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-11053 Description: When asked to both use a .netrc file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login and password. This update fixes this logic to avoid sending a password to the wrong host. References: - https://bugs.mageia.org/show_bug.cgi?id=33844 - https://curl.se/docs/CVE-2024-11053.html - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1... SRPMS: - 9/core/curl-7.88.1-4.5.mga9


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds