Lucene search

K
fedoraFedoraFEDORA:2480220C8466
HistoryApr 19, 2024 - 9:41 p.m.

[SECURITY] Fedora 40 Update: curl-8.6.0-8.fc40

2024-04-1921:41:45
lists.fedoraproject.org
9
fedora
update
curl
command line
data transfer
ftp
ftps
http
https
scp
sftp
tftp
telnet
dict
ldap
ldaps
file
imap
smtp
pop3
rtsp
ssl certificates
http post
http put
ftp uploading
proxies
cookies
authentication
file transfer resume
proxy tunneling
unix

8.6 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

9 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.5%

curl is a command line tool for transferring data with URL syntax, supporting FTP, FTPS, HTTP, HTTPS, SCP, SFTP, TFTP, TELNET, DICT, LDAP, LDAPS, FILE, IMA P, SMTP, POP3 and RTSP. curl supports SSL certificates, HTTP POST, HTTP PUT, FTP uploading, HTTP form based upload, proxies, cookies, user+password authentication (Basic, Digest, NTLM, Negotiate, kerberos…), file transfer resume, proxy tunneling and a busload of other useful tricks.

OSVersionArchitecturePackageVersionFilename
Fedora40anycurl< 8.6.0UNKNOWN

8.6 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

9 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.5%