Re: Curl vulnerability
Jeffrey Walton via curl-users <[email protected]>
| Newsgroups | gmane.comp.web.curl.general |
|---|---|
| Message-ID | <CAH8yC8nhZRyBtTd_OrL0S02fdyZEg3eE_WDmbq=kdE-+niQnJQ@mail.gmail.com> |
On Wed, Mar 6, 2024 at 4:41 PM Singh Bisht \ Anand via curl-users <[email protected]> wrote: > > > We have vulnerability of Curl in our environment which require to update curl to above or equal to 8.4 version. Could you provide us the steps to upgrade the curl without deleting or modifying the existing curl exe as we will be using deployment tool to update the curl. When we manually try to rename the existing file in order to place latest curl.exe file it gave error which says “ you require permission from trustedinstaller to make changes to file.” cURL is a default component of Windows. Microsoft should be updating it. See <https://curl.se/windows/microsoft.html> and <https://learn.microsoft.com/en-us/virtualization/community/team-blog/2017/20171219-tar-and-curl-come-to-windows>. Maybe you can reach out to Microsoft Global Security at <[email protected]>. I think they also respond to <[email protected]>. Jeff -- Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users Etiquette: https://curl.se/mail/etiquette.html