Curl CVE Countdown Anxiety
Description
The image is a GitHub discussion screenshot titled "Severity HIGH security problem to be announced with curl 8.4.0 on Oct 11 #12026." It shows bagder, marked as a maintainer, saying curl 8.4.0 will be released on October 11 with fixes for a severity HIGH CVE and one severity LOW CVE, describing the high issue as probably the worst curl security flaw in a long time. The visible bullets list "CVE-2023-38545: severity HIGH (affects both libcurl and the curl tool)" and "CVE-2023-38546: severity LOW (affects libcurl only, not the tool)," followed by "Now you know. Plan accordingly." The humor is the quiet panic of a foundational open-source dependency announcing a serious vulnerability window before details are public.
Comments
9Comment deleted
Every org discovered exactly how many critical paths were one shell script away from `curl | bash` becoming an incident response plan.
C:\>curl -V curl 8.0.1 (Windows) libcurl/8.0.1 Schannel WinIDN Comment deleted
A reminder that Shellshock was out in the wild for 25 years Comment deleted
Memes are supposed to be fun. This one is not. Comment deleted
The problem is not the problem. The problem is your attitude to the problem. Savvy? Comment deleted
I think he meant it in a humoristic way Comment deleted
Luckily for me, I am not an administrator, devops, developer or security specialist. So I may just laugh at this "yet another doomsday vulnerability". But I can almost feel the pain of all those unlucky people that may have to take urgent measures today. Comment deleted
.sh curl -V TGPy> curl 8.3.0 (x86_64-pc-linux-gnu) libcurl/8.3.0 OpenSSL/3.1.3 zlib/1.3 brotli/1.1.0 zstd/1.5.5 libidn2/2.3.4 libpsl/0.21.2 (+libidn2/2.3.4) libssh2/1.11.0 nghttp2/1.56.0 Release-Date: 2023-09-13 Protocols: dict file ftp ftps gopher gophers http https imap imaps mqtt pop3 pop3s rtsp scp sftp smb smbs smtp smtps telnet tftp Features: alt-svc AsynchDNS brotli GSS-API HSTS HTTP2 HTTPS-proxy IDN IPv6 Kerberos Largefile libz NTLM NTLM_WB PSL SPNEGO SSL threadsafe TLS-SRP UnixSockets zstd Comment deleted
lmao Comment deleted