Advertisement
Top
image credit: Vecteezy

Fresh curl tomorrow will patch ‘worst’ security flaw in ages

October 10, 2023

Start your patch engines – a new version of curl is due tomorrow that addresses a pair of flaws, one of which lead developer Daniel Stenberg describes as “probably the worst curl security flaw in a long time.”

Curl 8.4.0 will hit at around 0600 UTC (0800 CEST, 0700 BST, 0200 EST, 2300 PDT) on October 11 and deal with CVE-2023-38545, which affects both libcurl and the curl tool, and CVE-2023-38546, which only affects libcurl.

The release has no API or ABI changes, so the update should slot in without too much aggravation.

Read More on The Register