Curl 7.84

For discussions about security.
Post Reply
User avatar
8Geee
Posts: 376
Joined: Wed Jul 29, 2020 10:52 pm
Location: N.E. USA
Has thanked: 17 times
Been thanked: 54 times

Curl 7.84

Post by 8Geee »

An important revision to cURL is posted here because the first bug was INTRODUCED in version 7.69. The other two are reletively minor.

Rename of cookie file leads to Priviledge escalation.
This bug was introduced in curl 7.69.0. Versions before 7.69.0
DO NOT have this bug.

Improper (or delta) ftp pointer reference causes loss of file
information properties, especially filesize of download.

Do not use " as first pswd charater UNLESS the last character
is also ". Else the pswd will be terminated at a 'space' if
such exists.

Regards
8Geee

Money talks... no, it shouts, so that it doesn't have to hear common sense.

User avatar
bigpup
Moderator
Posts: 6405
Joined: Tue Jul 14, 2020 11:19 pm
Location: Earth, South Eastern U.S.
Has thanked: 760 times
Been thanked: 1326 times

Re: Curl 7.84

Post by bigpup »

I just checked my install of Fossapup64 9.5

It is using curl v7.68.0

You say Versions before 7.69.0
DO NOT have this bug.

So , I guess I am OK.

Forum Global Moderator
The things you do not tell us, are usually the clue to fixing the problem.
When I was a kid, I wanted to be older.
This is not what I expected :o

User avatar
8Geee
Posts: 376
Joined: Wed Jul 29, 2020 10:52 pm
Location: N.E. USA
Has thanked: 17 times
Been thanked: 54 times

Re: Curl 7.84

Post by 8Geee »

Unless some of the other security stuff 7.69 to 7.83 bothers you, you're good.

Money talks... no, it shouts, so that it doesn't have to hear common sense.

User avatar
wiak
Posts: 3673
Joined: Tue Dec 03, 2019 6:10 am
Location: Packing - big job
Has thanked: 57 times
Been thanked: 1028 times
Contact:

Re: Curl 7.84

Post by wiak »

This is where distro's based on Arch Linux are good since Arch a rolling release. Arch Linux core release at: curl 7.84.0-1
For this case, Fossa is okay(ish) since it's curl is 'old' at 7.68

https://www.tinylinux.info/
DOWNLOAD wd_multi for hundreds of 'distros' at your fingertips: viewtopic.php?p=99154#p99154
Αξίζει να μεταφραστεί;

ozsouth
Posts: 1396
Joined: Sun Jul 12, 2020 2:38 am
Location: S.E. Australia
Has thanked: 213 times
Been thanked: 614 times

Re: Curl 7.84

Post by ozsouth »

As I like ScPup64-20.06, I've kept updating openssl, wget & curl (can't get busybox to compile without errors). I did curl 7.83.1 last month, so thanks @8Geee for posting this. I've compiled 7.84 & added it to my ydrv. I needed a script in /etc/init.d to autoremove the older libcurl.so.4.7.0 file.

dimkr
Posts: 2002
Joined: Wed Dec 30, 2020 6:14 pm
Has thanked: 38 times
Been thanked: 912 times

Re: Curl 7.84

Post by dimkr »

wiak wrote: Sun Jul 03, 2022 5:50 am

This is where distro's based on Arch Linux are good since Arch a rolling release. Arch Linux core release at: curl 7.84.0-1
For this case, Fossa is okay(ish) since it's curl is 'old' at 7.68

It's a double-edged sword. They're the first to update to the new minor release that mitigates a vulnerability, but also the first to adopt a new major release that comes with new features and therefore introduces new vulnerabilities. (And, in some ways, newly-introduced vulnerabilities are more dangerous.)

IMHO, building a Puppy from a rolling release distro (and it doesn't matter if it's Void, Debian Sid or Slackware "current") is not a substitute for proper security and stability updates.

Post Reply

Return to “Security”