Skip to content
DevMeme
5087 of 7590
Security Post #5567 · source on Telegram

Curl CVE Countdown Anxiety

Description

The image is a GitHub discussion screenshot titled "Severity HIGH security problem to be announced with curl 8.4.0 on Oct 11 #12026." It shows bagder, marked as a maintainer, saying curl 8.4.0 will be released on October 11 with fixes for a severity HIGH CVE and one severity LOW CVE, describing the high issue as probably the worst curl security flaw in a long time. The visible bullets list "CVE-2023-38545: severity HIGH (affects both libcurl and the curl tool)" and "CVE-2023-38546: severity LOW (affects libcurl only, not the tool)," followed by "Now you know. Plan accordingly." The humor is the quiet panic of a foundational open-source dependency announcing a serious vulnerability window before details are public.

Comments

9
Anonymous ★ Top Pick Every org discovered exactly how many critical paths were one shell script away from `curl | bash` becoming an incident response plan.
  1. Anonymous ★ Top Pick

    Every org discovered exactly how many critical paths were one shell script away from `curl | bash` becoming an incident response plan.

  2. @Diotost 2y

    C:\>curl -V curl 8.0.1 (Windows) libcurl/8.0.1 Schannel WinIDN

    1. @chupasaurus 2y

      A reminder that Shellshock was out in the wild for 25 years

  3. @SamsonovAnton 2y

    Memes are supposed to be fun. This one is not.

    1. @Johnny_bit 2y

      The problem is not the problem. The problem is your attitude to the problem. Savvy?

      1. @RiedleroD 2y

        I think he meant it in a humoristic way

      2. @SamsonovAnton 2y

        Luckily for me, I am not an administrator, devops, developer or security specialist. So I may just laugh at this "yet another doomsday vulnerability". But I can almost feel the pain of all those unlucky people that may have to take urgent measures today.

  4. @sylfn 2y

    .sh curl -V TGPy> curl 8.3.0 (x86_64-pc-linux-gnu) libcurl/8.3.0 OpenSSL/3.1.3 zlib/1.3 brotli/1.1.0 zstd/1.5.5 libidn2/2.3.4 libpsl/0.21.2 (+libidn2/2.3.4) libssh2/1.11.0 nghttp2/1.56.0 Release-Date: 2023-09-13 Protocols: dict file ftp ftps gopher gophers http https imap imaps mqtt pop3 pop3s rtsp scp sftp smb smbs smtp smtps telnet tftp Features: alt-svc AsynchDNS brotli GSS-API HSTS HTTP2 HTTPS-proxy IDN IPv6 Kerberos Largefile libz NTLM NTLM_WB PSL SPNEGO SSL threadsafe TLS-SRP UnixSockets zstd

  5. @sylfn 2y

    lmao

Use J and K for navigation