Vulnerability Bulletins

DSA-3069 curl - security update

   
Affected software Debian
 
Symeon Paraschoudis discovered that the curl_easy_duphandle() functionin cURL, an URL transfer library, has a bug that can lead to libcurleventually sending off sensitive data that was not intended for sending,while performing a HTTP POST operation.

More info:

https://www.debian.org/security/2014/dsa-3069