Re: curl in Windows found vulnerable by scanners

Spork Schivago via curl-users <[email protected]>
Newsgroups gmane.comp.web.curl.general
Message-ID <CAEeNszYKBv2QFJ87xigT+6x-wtpgdFUicZck52Da1nSokgcS+g@mail.gmail.com>
On Wed, Nov 1, 2023, 18:31 Daniel Stenberg via curl-users <
[email protected]> wrote:

> Hello
>
> People keep emailing me about their security scanners finding that the
> curl
> tool version shipped in Windows contains several CVEs. (It still ships
> curl
> 8.0.1)
>
> I'm afraid that all parts of Windows, including the bundled curl tool, is
> managed by and shipped by Microsoft. Only they can upgrade Windows - and
> in
> this aspect curl is to be counted as a part of that.
>
> This email is posted here as an attempt to reach more people with this
> information.
>
> --
>
>   / daniel.haxx.se
>   | Commercial curl support up to 24x7 is available!
>   | Private help, bug fixes, support, ports, new features
>   | https://curl.se/support.html
> --
> Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users
> Etiquette:   https://curl.se/mail/etiquette.html


So for possible remediations to these vulnerabilities with curl 8.0.1 that
is bundled with Windows, we should reach out to Microsoft?

Thanks!

-- 
Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users
Etiquette:   https://curl.se/mail/etiquette.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.