bagder: curl-www/docs _security.html,1.12,1.13
| Newsgroups | gmane.comp.web.curl.www.cvs |
|---|---|
| Message-ID | <[email protected]> |
Update of /cvsroot/curl/curl-www/docs In directory labb:/tmp/cvs-serv24137 Modified Files: _security.html Log Message: added link to the Hardened-PHP Advisory Index: _security.html =================================================================== RCS file: /cvsroot/curl/curl-www/docs/_security.html,v retrieving revision 1.12 retrieving revision 1.13 diff -u -d -r1.12 -r1.13 --- _security.html 7 Dec 2005 10:11:57 -0000 1.12 +++ _security.html 7 Dec 2005 12:55:52 -0000 1.13 @@ -44,7 +44,10 @@ <tr><td>Affected versions</td><td>curl and libcurl 7.11.2 to and including 7.15.0</td></tr> <tr><td>Not affected versions</td><td>curl and libcurl 7.11.1 and earlier, 7.15.1 and later</td></tr> <tr><td>Patch</td><td><a href="http://curl.haxx.se/libcurl-urllen.patch">libcurl-urllen.patch</a></td></tr> - <tr><td>Advisories</td><td><a href="adv_20051207.html">Project cURL Security Advisory</a></td></tr> + + <tr><td>Advisories</td><td><a href="adv_20051207.html">Project cURL Security + Advisory</a> <a href="http://www.hardened-php.net/advisory_242005.109.html">Hardened-PHP Advisory</a></td></tr> + </table> <p> libcurl's URL parser function can overflow a malloced buffer in two ways, if