Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

libcurl vuln #397

Open
Sharyie opened this issue Oct 11, 2023 · 2 comments
Open

libcurl vuln #397

Sharyie opened this issue Oct 11, 2023 · 2 comments
Assignees

Comments

@Sharyie
Copy link

Sharyie commented Oct 11, 2023

This package points to an old ref of libcurl related to https://daniel.haxx.se/blog/2023/10/11/how-i-made-a-heap-overflow-in-curl/.

Could you update it?

@nktnet1
Copy link

nktnet1 commented Oct 17, 2023

@Sharyie your link sends us to "https://github.com/JCMais/node-libcurl/issues/url" when clicked on, so I'll leave the raw text to the blog post here:

P.S. Snyk security also picked up on these two vulnerabilities:

  1. Heap-based Buffer Overflow (high, 7.7)
  2. External Control of File Name or Path (low, 3.7)

@JCMais
Copy link
Owner

JCMais commented Oct 30, 2023

I will try to start the upgrade process this weekend, however updating to 8.4 will take some time, so no promises here.

For now, my advice would be to follow the recommendations in the advisory.

@JCMais JCMais self-assigned this Oct 30, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants