Re: Is there anything for the outdated curl.exe? CVE-2022-43552

Jeffrey Walton via curl-users <[email protected]>
Newsgroups gmane.comp.web.curl.general
Message-ID <CAH8yC8m3gN4z9DAYOJLkYt1jaPSDsWvsYw6PAboKn7+0nH8AmA@mail.gmail.com>
On Mon, Apr 3, 2023 at 11:17 AM Daniel Stenberg via curl-users
<[email protected]> wrote:
>
> On Mon, 3 Apr 2023, maxcoder1 via curl-users wrote:
>
> > Is there anything for the outdated curl.exe? CVE-2022-43552
> >
> > edit: a fully patched w10 / 2019 / 2022 is showing 7.83.1.
>
> See https://curl.se/windows/microsoft.html
>
> When you install Windows, your vendor is called Microsoft and they are
> responsible for the software bundled with their operating system. Please ask
> them about their updates.

+1. Microsoft Global Security ([email protected]) may be a good
place to drop a note.

> > Also , if I install the latest version of CURL from https://curl.se/windows/
> > , will it cause any problems?
>
> If you overwrite/delete the old one I suspect it might, yes.

System File Checker (SFC) may not allow that to happen. Or if it
happens, then SFC will restore the old [vulnerable] file because the
tool believes the file is corrupted.

https://support.microsoft.com/en-us/topic/use-the-system-file-checker-tool-to-repair-missing-or-corrupted-system-files-79aa86cb-ca52-166a-92a3-966e85d4094e

Jeff
-- 
Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users
Etiquette:   https://curl.se/mail/etiquette.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.