Ubuntu Security Notice USN-6535-1

Discussion in 'News Aggregator' started by Packet Storm, 8 Dec 2023.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 6535-1 - Harry Sintonen discovered that curl incorrectly handled mixed case cookie domains. A remote attacker could possibly use this issue to set cookies that get sent to different and unrelated sites and domains. Maksymilian Arciemowicz discovered that curl incorrectly handled long file names when saving HSTS data. This could result in curl losing HSTS data, and subsequent requests to a site would be done without it, contrary to expectations. This issue only affected Ubuntu 23.04 and Ubuntu 23.10.

    Continue reading...
     

Share This Page

Loading...