Name: | curl |
---|---|
Version: | 7.61.1 |
Release: | 22.el8 |
Architecture: | aarch64 |
Group: | Unspecified |
Size: | 733541 |
License: | MIT |
RPM: | curl-7.61.1-22.el8.aarch64.rpm |
Source RPM: | curl-7.61.1-22.el8.src.rpm |
Build Date: | Wed Nov 10 2021 |
Build Host: | build-ol8-aarch64.oracle.com |
Vendor: | Oracle America |
URL: | https://curl.haxx.se/ |
Summary: | A utility for getting files from remote servers (FTP, HTTP, and others) |
Description: | curl is a command line tool for transferring data with URL syntax, supporting FTP, FTPS, HTTP, HTTPS, SCP, SFTP, TFTP, TELNET, DICT, LDAP, LDAPS, FILE, IMAP, SMTP, POP3 and RTSP. curl supports SSL certificates, HTTP POST, HTTP PUT, FTP uploading, HTTP form based upload, proxies, cookies, user+password authentication (Basic, Digest, NTLM, Negotiate, kerberos...), file transfer resume, proxy tunneling and a busload of other useful tricks. |
- fix STARTTLS protocol injection via MITM (CVE-2021-22947) - fix protocol downgrade required TLS bypass (CVE-2021-22946)
- fix TELNET stack contents disclosure again (CVE-2021-22925) - fix TELNET stack contents disclosure (CVE-2021-22898) - fix bad connection reuse due to flawed path name checks (CVE-2021-22924) - disable metalink support to fix the following vulnerabilities CVE-2021-22923 - metalink download sends credentials CVE-2021-22922 - wrong content via metalink not discarded
- fix a cppcheck's false positive in 0029-curl-7.61.1-CVE-2021-22876.patch
- make `curl --head file://` work as expected (#1947493) - prevent automatic referer from leaking credentials (CVE-2021-22876)
- http: send payload when (proxy) authentication is done (#1918692) - curl: Inferior OCSP verification (CVE-2020-8286) - libcurl: FTP wildcard stack overflow (CVE-2020-8285) - curl: trusting FTP PASV responses (CVE-2020-8284)
- validate an ssl connection using an intermediate certificate (#1895355)
- fix multiarch conflicts in libcurl-minimal (#1895391)
- do not crash when HTTPS_PROXY and NO_PROXY are used together (#1873327) - libcurl: wrong connect-only connection (CVE-2020-8231)
- avoid overwriting a local file with -J (CVE-2020-8177)
- load built-in openssl engines (#1854369)