First published: Mon Nov 18 2024(Updated: )
It was discovered that curl could overwrite the HSTS expiry of the parent domain with the subdomain's HSTS entry. This could lead to curl switching back to insecure HTTP earlier than otherwise intended, resulting in information exposure.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/curl | <8.9.1-2ubuntu2.1 | 8.9.1-2ubuntu2.1 |
Ubuntu Ubuntu | =24.10 | |
All of | ||
ubuntu/libcurl3t64-gnutls | <8.9.1-2ubuntu2.1 | 8.9.1-2ubuntu2.1 |
Ubuntu Ubuntu | =24.10 | |
All of | ||
ubuntu/libcurl4t64 | <8.9.1-2ubuntu2.1 | 8.9.1-2ubuntu2.1 |
Ubuntu Ubuntu | =24.10 | |
All of | ||
ubuntu/curl | <8.5.0-2ubuntu10.5 | 8.5.0-2ubuntu10.5 |
Ubuntu Ubuntu | =24.04 | |
All of | ||
ubuntu/libcurl3t64-gnutls | <8.5.0-2ubuntu10.5 | 8.5.0-2ubuntu10.5 |
Ubuntu Ubuntu | =24.04 | |
All of | ||
ubuntu/libcurl4t64 | <8.5.0-2ubuntu10.5 | 8.5.0-2ubuntu10.5 |
Ubuntu Ubuntu | =24.04 | |
All of | ||
ubuntu/curl | <7.81.0-1ubuntu1.19 | 7.81.0-1ubuntu1.19 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/libcurl3-gnutls | <7.81.0-1ubuntu1.19 | 7.81.0-1ubuntu1.19 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/libcurl3-nss | <7.81.0-1ubuntu1.19 | 7.81.0-1ubuntu1.19 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/libcurl4 | <7.81.0-1ubuntu1.19 | 7.81.0-1ubuntu1.19 |
Ubuntu Ubuntu | =22.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.