2020年8月26日 星期三

[USN-4466-1] curl vulnerability

 ---------- Forwarded message ---------

From: Marc Deslauriers <marc.deslauriers@canonical.com>

Date: Aug 19, 2020 9:06PM

Marc Aldorasi discovered that curl incorrectly handled the libcurl

CURLOPT_CONNECT_ONLY option. This could result in data being sent to the

wrong destination, possibly exposing sensitive information.

References:

  https://usn.ubuntu.com/4466-1

  CVE-2020-8231

沒有留言:

張貼留言