In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsThere is no fixed version for Debian:unstable
curl
.
Note: Versions mentioned in the description apply only to the upstream curl
package and not the curl
package as distributed by Debian
.
See How to fix?
for Debian:unstable
relevant fixed versions and status.
When asked to use a .netrc
file for credentials and to follow HTTP
redirects, curl could leak the password used for the first host to the
followed-to host under certain circumstances.
This flaw only manifests itself if the netrc file has a default
entry that
omits both login and password. A rare circumstance.