CVE-2024-5535 is an #OpenSSL problem that cannot be triggered by #curl
OpenSSL calls it it a low severity flaw. openssl.org/news/vulnerabiliti…
GitHub lists it as "critical" at 9.1 out of 10: github.com/advisories/GHSA-4fc…
This entry was edited (4 months ago)
daniel:// stenberg://
in reply to daniel:// stenberg:// • • •p
in reply to daniel:// stenberg:// • • •@bagder
Bernard Quatermass
in reply to daniel:// stenberg:// • • •Speaking as someone who is dealing with that as a OSS project member live-and-direct-this-instant, I couldn't agree more.
We're not a CNA (nor are we particularly bothered in becoming one), and as you've noted that doesn't do much to stop the garbage.
Jim Fuller
in reply to daniel:// stenberg:// • • •Tim Yates
in reply to daniel:// stenberg:// • • •Clemens
in reply to daniel:// stenberg:// • • •