Vulnerability Bulletins |
DSA-3122 curl - security update |
|
| Affected software | Debian |
|
Andrey Labunets of Facebook discovered that cURL, an URL transferlibrary, fails to properly handle URLs with embedded end-of-linecharacters. An attacker able to make an application using libcurl toaccess a specially crafted URL via an HTTP proxy could use this flaw todo additional requests in a way that was not intended, or insertadditional request headers into the request. More info: https://www.debian.org/security/2015/dsa-3122 |
|






