Ubuntu Security Update USN-7104-1: curl vulnerability

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,843
Reaction score
74
Credits
-1,257
It was discovered that curl could overwrite the HSTS expiry of the parent domain with the subdomain's HSTS entry. This could lead to curl switching back to insecure HTTP earlier than otherwise intended, resulting in information exposure.

Continue reading...
 


Follow Linux.org

Staff online

Members online


Top