Path to this page:
Subject: CVS commit: pkgsrc/www/curl
From: Thomas Klausner
Date: 2023-03-20 08:45:57
Message id: 20230320074557.8882EFA90@cvs.NetBSD.org
Log Message:
curl: update to 8.0.0.
Exactly one month since the previous release, we are happy to give
you curl 8.0.0 released on curl’s official 25th birthday.
This a major version number bump but without any ground-breaking
changes or fireworks. We decided it was about time to reset the
minor number down to more a manageable level and doing it exactly
on curl’s 25th birthday made it extra fun. There is no API nor ABI
break in this version.
We disclose six new vulnerabilities today, five of them at severity
Low and one of them at Medium.
CVE-2023-27533: TELNET option IAC injection
CVE-2023-27534: SFTP path ~ resolving discrepancy
CVE-2023-27535: FTP too eager connection reuse
CVE-2023-27536: GSS delegation too eager connection re-use
CVE-2023-27537: HSTS double-free
CVE-2023-27538: SSH connection too eager reuse still
Files: