VYPR

rpm package

suse/curl&distro=SUSE Manager Server LTS 4.3

pkg:rpm/suse/curl&distro=SUSE%20Manager%20Server%20LTS%204.3

Vulnerabilities (2)

  • CVE-2025-9086HigSep 12, 2025
    affected < 8.14.1-150400.5.69.1fixed 8.14.1-150400.5.69.1

    1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with just a slash as path

  • CVE-2025-10148MedSep 12, 2025
    affected < 8.14.1-150400.5.69.1fixed 8.14.1-150400.5.69.1

    curl's websocket code did not update the 32 bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traf