Curl Project Squashes High-Severity Bug in Omnipresent libcurl Library

Curl v8.4.0 is out and fixes among other things a high-severity SOCKS5 heap buffer overflow vulnerability (CVE-2023-38545). Appropriate patches for some older curl versions have been released, too.

The post Curl Project Squashes High-Severity Bug in Omnipresent libcurl Library appeared first on Linux Today.



Source: Linux Today – Curl Project Squashes High-Severity Bug in Omnipresent libcurl Library

Raspberry Pi OS Is Now Based on Debian Bookworm, Supports Raspberry Pi 5

The biggest change in the new Raspberry Pi OS release is that it’s now based on the latest Debian GNU/Linux 12 “Bookworm” operating system series.

The post Raspberry Pi OS Is Now Based on Debian Bookworm, Supports Raspberry Pi 5 appeared first on Linux Today.



Source: Linux Today – Raspberry Pi OS Is Now Based on Debian Bookworm, Supports Raspberry Pi 5

Curl 8.4.0 released

Version
8.4.0
of the curl data-transfer tool has been released, mostly in
response to a relatively severe security vulnerability that can be
triggered when a SOCKS5 proxy server is in use. See this
blog post
for details on what went wrong. “In hindsight, shipping a
heap overflow in code installed in over twenty billion instances is not an
experience I would recommend.


Source: LWN.net – Curl 8.4.0 released