AIX Open Source

AIX Open Source

Share your experiences and connect with fellow developers to discover how to build and manage open source software for the AIX operating system

 View Only
  • 1.  Security Advisory Curl - Update to 8.4.0 or higher needed

    Posted Fri October 06, 2023 03:00 AM

    Hi AIX OpenSource-Team,

    please update curl, because of various security issues:


    AFFECTED VERSIONS:
    curl < 8.4.0

    AIX-Toolbox:
    8.2.1

    CVE:

    CVE-2023-38545: severity HIGH (affects both libcurl and the curl tool)

    CVE-2023-38546: severity LOW (affects libcurl only, not the tool)

    Severity HIGH security problem to be announced with curl 8.4.0 on Oct 11 · curl/curl · Discussion #12026 · GitHub



    ------------------------------
    Tobias Schröer
    ------------------------------


  • 2.  RE: Security Advisory Curl - Update to 8.4.0 or higher needed

    Posted Fri October 06, 2023 08:12 AM

    Hi Tobias,

    Thanks for the info.

    We will update to latest available version soon.



    ------------------------------
    SANGAMESH
    ------------------------------



  • 3.  RE: Security Advisory Curl - Update to 8.4.0 or higher needed

    Posted Thu October 12, 2023 11:34 PM

    Hi Tobias,

    For CVE-2023-38545: severity HIGH (affects both libcurl and the curl tool) vulnerability if we upgrade curl version to 8.2.1 will it resolve this vulnerability.There is no 8.4.0 package in toolbox and for only curl package is present how can we get libcurl package also.

    Can you please reply on priority.

    Regards,

    Subba Reddem



    ------------------------------
    Subba Reddy Reddem
    ------------------------------



  • 4.  RE: Security Advisory Curl - Update to 8.4.0 or higher needed

    Posted Thu October 26, 2023 08:08 PM

    curl-8.4.0-1.aix7.1.ppc.rpm is available on the toolbox.



    ------------------------------
    Jan Harris
    AIX Development Support (Liaison to the AIX Toolbox for Open Source)
    IBM (Contract)
    Austin TX
    ------------------------------