Upcoming Vulnerability Disclosure for cURL

Upcoming Vulnerability Disclosure for cURL

On October 3, Daniel Stenberg (@badger) announced a forthcoming patch for cURL (version 8.4.0) that will be released on October 11, which includes a fix for a still unknown "high severity CVE".

Due to the widespread usage of curl, this vulnerability has the potential to be a major security risk.

Organizations are strongly encouraged to begin identifying where curl is used within their environment so that patches can be applied in a timely manner once they are released. 

PacketWatch's Andrew Oesterheld has created several queries that can be used across various platforms to help identify where cURL is used.

curl_page-0001

You can download a copy of the .pdf file by filling out the form below:

 

Cyber Threat Intelligence Report

8 min read

Cyber Threat Intelligence Report

This week, we briefed our clients on the new Ghost-sender Email Spoofing research from InfoGuard Labs. Be sure to test your domain for the...

Read More
Cyber Threat Intelligence Report

7 min read

Cyber Threat Intelligence Report

This week, we briefed our clients on new social engineering attacks targeting law firms. The Silent Ransomware Group has been showing up in person.

Read More
Cyber Threat Intelligence Report

7 min read

Cyber Threat Intelligence Report

This week, we briefed our clients on the recent increase in Device Code Phishing attacks and how to protect themselves, starting with Microsoft 365.

Read More
Future Team Sixty43 Reports.
Be notified when Cyber Threat Intelligence or Threat Profile reports are published.