Vulnerability Bulletins

DSA-3122 curl - security update

   
Affected software Debian
 
Andrey Labunets of Facebook discovered that cURL, an URL transferlibrary, fails to properly handle URLs with embedded end-of-linecharacters. An attacker able to make an application using libcurl toaccess a specially crafted URL via an HTTP proxy could use this flaw todo additional requests in a way that was not intended, or insertadditional request headers into the request.

More info:

https://www.debian.org/security/2015/dsa-3122