HomeSecurityVulnerability in Curl allows hackers to access sensitive data

Vulnerability in Curl allows hackers to access sensitive data

A critical vulnerability, known as CVE-2024-11053, has been identified in the Curl, which could allow hackers to intercept sensitive information.

curl vulnerability

This vulnerability affects versions 6.5 through 8.11.0 and is likely to cause password leakage when Curl uses .netrc files and follows HTTP redirects.

Read more: Cleo fixes critical zero-day exploited in attacks

Although the severity of this vulnerability is rated as “Low”, the importance of fixing it remains high.

On December 11, 2024, Curl released version 8.11.1, which resolves the issue.

Recommendations for users:

See more: Hunk Companion: Critical vulnerability in WordPress plugin

  • Upgrade immediately to version 8.11.1.
  • If the upgrade is not possible, apply the relevant patch.
  • Avoid using .netrc files in conjunction with HTTP redirects.

The vulnerability in the Curl project was reported on November 8, 2024. After thorough analysis and patching, the curl development team contacted distros@openwall on December 3, 2024. The official release of curl version 8.11.1, accompanied by this security advisory, was scheduled for December 11, 2024, at approximately 06:00 UTC.

curl vulnerability

Administrators and users are urged to check their Curl settings and immediately upgrade to the latest version, thus ensuring their protection from this security vulnerability.

Read more: Vulnerability discovered in macOS WorkflowKit Race

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS