DSA-5587-1 curl -- security update

Related Vulnerabilities: CVE-2023-46218   CVE-2023-46219  

Two security issues were discovered in Curl: Cookies were incorrectly validated against the public suffix list of domains and in same cases HSTS data could fail to save to disk. For the oldstable distribution (bullseye), these problems have been fixed in version 7.74.0-1.3+deb11u11. For the stable distribution (bookworm), these problems have been fixed in version 7.88.1-10+deb12u5. We recommend that you upgrade your curl packages. For the detailed security status of curl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/curl

Debian Security Advisory

DSA-5587-1 curl -- security update

Date Reported:
23 Dec 2023
Affected Packages:
curl
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2023-46218, CVE-2023-46219.
More information:

Two security issues were discovered in Curl: Cookies were incorrectly validated against the public suffix list of domains and in same cases HSTS data could fail to save to disk.

For the oldstable distribution (bullseye), these problems have been fixed in version 7.74.0-1.3+deb11u11.

For the stable distribution (bookworm), these problems have been fixed in version 7.88.1-10+deb12u5.

We recommend that you upgrade your curl packages.

For the detailed security status of curl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/curl