A critical vulnerability, known as CVE-2024-11053, has been identified in the Curl, which could allow hackers to intercept sensitive information.

This vulnerability affects versions 6.5 through 8.11.0 and is likely to cause password leakage when Curl uses .netrc files and follows HTTP redirects.
Read more: Cleo fixes critical zero-day exploited in attacks
Although the severity of this vulnerability is rated as “Low”, the importance of fixing it remains high.
On December 11, 2024, Curl released version 8.11.1, which resolves the issue.
Recommendations for users:
See more: Hunk Companion: Critical vulnerability in WordPress plugin
- Upgrade immediately to version 8.11.1.
- If the upgrade is not possible, apply the relevant patch.
- Avoid using .netrc files in conjunction with HTTP redirects.
The vulnerability in the Curl project was reported on November 8, 2024. After thorough analysis and patching, the curl development team contacted distros@openwall on December 3, 2024. The official release of curl version 8.11.1, accompanied by this security advisory, was scheduled for December 11, 2024, at approximately 06:00 UTC.

Administrators and users are urged to check their Curl settings and immediately upgrade to the latest version, thus ensuring their protection from this security vulnerability.
Read more: Vulnerability discovered in macOS WorkflowKit Race
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
