RE: curl in Windows found vulnerable by scanners

Bill Mercer via curl-users <[email protected]>
Newsgroups gmane.comp.web.curl.general
Message-ID <BN8PR15MB29135BA91E6019EE15AA8E21BBA6A@BN8PR15MB2913.namprd15.prod.outlook.com>
> I've been told that a new curl version arrives “in a coming security update”.

Removing or replacing the MS version is problematic because its protected under trusted installer. 
For mitigation you can place a newer curl version in a higher path so it gets executed by default, and you can use application control policy to prevent execution of the older versions, but the MS version will still show up if you're doing file scanning, so your best option is probably to request an exception on the scan until MS gets their act together. 



 



-- 
Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users
Etiquette:   https://curl.se/mail/etiquette.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.