USN-7104-1: curl vulnerability
It was discovered that curl could overwrite the HSTS expiry of the parent domain with the subdomain's HSTS entry. This could lead to curl switching back to insecure HTTP earlier than otherwise intended, resulting in information exposure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7104-1?
The severity of USN-7104-1 is critical as it can lead to information exposure by causing curl to revert to insecure HTTP.
How do I fix USN-7104-1?
To fix USN-7104-1, upgrade to the remedied versions of curl and its associated libraries as specified in the security advisory.
Which software is affected by USN-7104-1?
USN-7104-1 affects curl and several libraries associated with curl on Ubuntu versions 22.04, 24.04, and 24.10.
What vulnerabilities does USN-7104-1 address?
USN-7104-1 addresses a vulnerability where curl can overwrite the HSTS expiry of a parent domain with a subdomain's entry.
What is HSTS and why is it important in relation to USN-7104-1?
HSTS, or HTTP Strict Transport Security, is crucial for enforcing secure connections, and its compromise can lead to a significant reduction in security.