Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump curl from 8.8.0 to 8.9.1 #206

Merged
merged 1 commit into from
Aug 8, 2024

Conversation

ryfu-msft
Copy link
Contributor

Address another component governance issue: CVE-2024-7264

cURL / libcURL contains an out-of-bounds read flaw in the GTime2str() function in lib/vtls/x509asn1.c that is triggered when parsing a syntactically incorrect ASN.1 Generalized Time field. This may allow a context-dependent attacker to crash a process linked against the library or potentially disclose memory contents.

This is fixed in the latest version of curl (8.9.1)

@ryfu-msft ryfu-msft requested a review from a team as a code owner August 8, 2024 20:23
@arthuraraujo-msft arthuraraujo-msft changed the title update curl to 8.9.1 Bump curl from 8.8.0 to 8.9.1 Aug 8, 2024
@arthuraraujo-msft arthuraraujo-msft merged commit be733af into microsoft:main Aug 8, 2024
3 checks passed
@ryfu-msft ryfu-msft deleted the curlUpdate branch August 8, 2024 20:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants