Skip to content

docs: add warnings about FILE: URLs on Windows#5066

Closed
bagder wants to merge 2 commits intomasterfrom
bagder/windows-file-warning
Closed

docs: add warnings about FILE: URLs on Windows#5066
bagder wants to merge 2 commits intomasterfrom
bagder/windows-file-warning

Conversation

@bagder
Copy link
Copy Markdown
Member

@bagder bagder commented Mar 10, 2020

  • --url man page section
  • libcurl-security.3 gets the full text
  • CURLOPT_URL.3

Reported-by: Tim Sedlmeyer (via hackerone)


I intend to also:

  • send a special "warning" to the curl-library mailing list
  • blog about it
  • update the CVE-2019-15601 description to backpedal accordingly

I want to merge/post this information (no earlier than) March 16th to not make it get lost too much in the regular release noise this week.

To discuss: should we retract CVE-2019-15601 from the list of curl vulnerabilities or doesn't it matter?

 - --url man page section
 - libcurl-security.3 gets the full text
 - CURLOPT_URL.3

Reported-by: Tim Sedlmeyer
Copy link
Copy Markdown
Contributor

@kdudka kdudka left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice reading.

@bagder
Copy link
Copy Markdown
Member Author

bagder commented Mar 13, 2020

I'll merge now, and announce per mail and blog on Monday.

@bagder
Copy link
Copy Markdown
Member Author

bagder commented Mar 13, 2020

Merged 0845ecb

@bagder bagder closed this Mar 13, 2020
@bagder bagder deleted the bagder/windows-file-warning branch March 13, 2020 15:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Development

Successfully merging this pull request may close these issues.

3 participants