microsoft / sfs-client

Simple File Solution (SFS) Client
MIT License
15 stars 13 forks source link

Bump curl from 8.8.0 to 8.9.1 #206

Closed ryfu-msft closed 3 months ago

ryfu-msft commented 3 months ago

Address another component governance issue: CVE-2024-7264

cURL / libcURL contains an out-of-bounds read flaw in the GTime2str() function in lib/vtls/x509asn1.c that is triggered when parsing a syntactically incorrect ASN.1 Generalized Time field. This may allow a context-dependent attacker to crash a process linked against the library or potentially disclose memory contents.

This is fixed in the latest version of curl (8.9.1)