ELA-982-1 curl security update

cookie injection

2023-10-11
Packagecurl
Version7.38.0-4+deb8u27 (jessie), 7.52.1-5+deb9u20 (stretch)
Related CVEs CVE-2023-38546


An issue was found in Curl, an easy-to-use client-side URL transfer library and command line tool, which could lead to cookie injection from a file named none under certain circumstances.



For Debian 8 jessie, these problems have been fixed in version 7.38.0-4+deb8u27.

For Debian 9 stretch, these problems have been fixed in version 7.52.1-5+deb9u20.

We recommend that you upgrade your curl packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.