Vulnerability Bulletins |
DSA-3240 curl - security update |
|
| Affected software | Debian |
|
It was discovered that cURL, an URL transfer library, if configured touse a proxy server with the HTTPS protocol, by default could send to theproxy the same HTTP headers it sends to the destination server, possiblyleaking sensitive information. More info: https://www.debian.org/security/2015/dsa-3240 |
|






