Re: Curl vulnerability

Jeffrey Walton via curl-users <[email protected]>
Newsgroups gmane.comp.web.curl.general
Message-ID <CAH8yC8nhZRyBtTd_OrL0S02fdyZEg3eE_WDmbq=kdE-+niQnJQ@mail.gmail.com>
On Wed, Mar 6, 2024 at 4:41 PM Singh Bisht \ Anand via curl-users
<[email protected]> wrote:
>
>
> We have vulnerability of Curl in our environment which require to update curl to above or equal to 8.4 version. Could you provide us the steps to upgrade the curl without deleting or modifying the existing curl exe as we will be using deployment tool to update the curl. When we manually try to rename the existing file in order to place latest curl.exe file it gave error which says “  you require permission  from trustedinstaller to make changes to file.”

cURL is a default component of Windows. Microsoft should be updating
it. See <https://curl.se/windows/microsoft.html> and
<https://learn.microsoft.com/en-us/virtualization/community/team-blog/2017/20171219-tar-and-curl-come-to-windows>.

Maybe you can reach out to Microsoft Global Security at
<[email protected]>. I think they also respond to
<[email protected]>.

Jeff
-- 
Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users
Etiquette:   https://curl.se/mail/etiquette.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.