Tuesday, February 9, 2010

libcurl security vulnerability is fixed in the recent release (7.20.0)

libcurl 7.20.0 is released by fixing a vulnerability described in Security Advisory February 9 2010 . Maintainers of the binary distributions are suggested to take one of the following actions as soon as possible:

A - Upgrade to curl and libcurl 7.20.0
B - Apply this patch and rebuild
C - Disable automatic content encoding decompression in your application
D - Rebuild curl without zlib support
E - change your code to use 4*CURL_MAX_WRITE_SIZE for buffer sizes

0 comments:

Post a Comment