Cybersecurity

Critical Heap Overflow Vulnerability in Curl Fixed After a Week Long Wait | Cyware Hacker News

Executive Summary On October 4, a high-severity security vulnerability was reported and fixed in curl. The vulnerability, CVE-2023-38545, was associated with a severe heap overflow during the SOCKS5 proxy handshake process, impacting both the libcurl and the curl tool.  This article whirls around a detailed analysis of the issue, its cause, its potential risks, and […]

Cybersecurity

Security Patch for Two New Flaws in Curl Library Arriving on October 11

Oct 09, 2023NewsroomSoftware Security / Vulnerability The maintainers of the Curl library have released an advisory warning of two security vulnerabilities that are expected to be addressed as part of an forthcoming update set for release on October 11, 2023. This includes a high-severity and a low-severity flaw tracked under the identifiers CVE-2023-38545 and CVE-2023-38546, […]