Re: curl in Windows found vulnerable by scanners
Spork Schivago via curl-users <[email protected]>
| Newsgroups | gmane.comp.web.curl.general |
|---|---|
| Message-ID | <CAEeNszYKBv2QFJ87xigT+6x-wtpgdFUicZck52Da1nSokgcS+g@mail.gmail.com> |
On Wed, Nov 1, 2023, 18:31 Daniel Stenberg via curl-users < [email protected]> wrote: > Hello > > People keep emailing me about their security scanners finding that the > curl > tool version shipped in Windows contains several CVEs. (It still ships > curl > 8.0.1) > > I'm afraid that all parts of Windows, including the bundled curl tool, is > managed by and shipped by Microsoft. Only they can upgrade Windows - and > in > this aspect curl is to be counted as a part of that. > > This email is posted here as an attempt to reach more people with this > information. > > -- > > / daniel.haxx.se > | Commercial curl support up to 24x7 is available! > | Private help, bug fixes, support, ports, new features > | https://curl.se/support.html > -- > Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users > Etiquette: https://curl.se/mail/etiquette.html So for possible remediations to these vulnerabilities with curl 8.0.1 that is bundled with Windows, we should reach out to Microsoft? Thanks! -- Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users Etiquette: https://curl.se/mail/etiquette.html