Skip to content

Conversation

@bagder
Copy link
Member

@bagder bagder commented Jan 19, 2025

libcurl cannot fully protect against attacks where an attacker has write access to the same directory where it is directed to save files. This is particularly sensitive if you save files using elevated privileges.

Previously only mentioned in VULN-DISCLOSURE-POLICY.md.

Highlighted-by: Donguk Kim

libcurl cannot fully protect against attacks where an attacker has write
access to the same directory where it is directed to save files. This is
particularly sensitive if you save files using elevated privileges.

Previously also mentioned in VULN-DISCLOSURE-POLICY.md.

Highlighted-by: Donguk Kim
@bagder bagder closed this in 0f54bfd Jan 20, 2025
@bagder bagder deleted the bagder/docs-save-security branch January 20, 2025 09:35
pps83 pushed a commit to pps83/curl that referenced this pull request Apr 26, 2025
libcurl cannot fully protect against attacks where an attacker has write
access to the same directory where it is directed to save files. This is
particularly sensitive if you save files using elevated privileges.

Previously only mentioned in VULN-DISCLOSURE-POLICY.md.

Highlighted-by: Donguk Kim

Closes curl#16051
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

1 participant