Severity HIGH security problem to be announced with curl 8.4.0 on Oct 11 (CVE-2023-38545) · curl/curl · Discussion #12026

https://github.com/curl/curl/discussions/12026

Posted on twitter by Curl author Daniel Stenberg - https://nitter.cz/bagder/status/1709103920914526525

We are cutting the release cycle short and will release curl 8.4.0 on October 11, including a fix for a severity HIGH CVE. Buckle up.

... But this time actually the worst security problem found in curl in a long time

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-38545

66 points · 8 comments · view on lemmy.world

8 Comments

Black616Angel@feddit.de · 14 pts · 2y (7 replies)

Who also guesses buffer overflow or use-after-free?

ultratiem@lemmy.ca · 12 pts · 2y (1 reply)

Buffer overflows are like Lupus in House M.D.

__init__@programming.dev · 5 pts · 2y

It’s not overflow. It’s never overflow.

aoidenpa@lemmy.world · -5 pts · 2y (4 replies)

Why don't they just rewrite it in rust? It would be much safer right?

unquietwiki@programming.dev · 16 pts · 2y

I think that's been asked before. That'd be a massive undertaking, and they also support architectures that I don't think Rust does (yet).

fil@programming.dev · 2 pts · 2y (1 reply)

You can already use experimental hyper backend (written in rust) for http stuff in curl https://aws.amazon.com/blogs/opensource/how-using-hyper-in-curl-can-help-make-the-internet-safer/ I wonder if the vulnerability touches this use case as well

aoidenpa@lemmy.world · 1 pts · 2y

Perfect article for my question. Appreciated.

charonn0@startrek.website · 1 pts · 2y
[ removed ]
MajorHavoc@lemmy.world · 12 pts · 2y

I want to thank the curl developers for taking security issues seriously to keep me safe.

Now I'm going to go pipe another curl script output directly into a sudo bash command. /s

We need a version of /s for "I'm not actually doing this right now... but we know I still will..."