Описание
When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| curl | fixed | 8.20.0~rc3-1 | package | |
| curl | fixed | 8.14.1-2+deb13u4 | trixie | package |
| curl | no-dsa | bookworm | package | |
| curl | postponed | bullseye | package |
Примечания
https://curl.se/docs/CVE-2026-6429.html
Introduced by: https://github.com/curl/curl/commit/01165e08e0d131b399fba2190f17af67e66f0888 (curl-7_14_0)
Fixed by: https://github.com/curl/curl/commit/b4024bf808bd558026fdc6096e8457f199ace306 (rc-8_20_0-3)
Связанные уязвимости
When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.
When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.
When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.
When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.