"Curl 8.4.0 will hit at around 0600 UTC (0800 CEST, 0700 BST, 0200 EST, 2300 PDT) on October 11 and deal with CVE-2023-38545, which affects both libcurl and the curl tool, and CVE-2023-38546, which only affects libcurl...."
Fresh curl tomorrow will patch 'worst' security flaw in ages | TheRegister
https://www.theregister.com/2023/10/10/curl_patch_in_update/
1 Comments
charonn0@startrek.website · 1 pts · 2y
It's a heap overflow: https://daniel.haxx.se/blog/2023/10/11/how-i-made-a-heap-overflow-in-curl/