Windows 10: Updating Microsoft Curl to the most recent version. Curl 7.84 <= 8.2.1 Header DoS...

Discus and support Updating Microsoft Curl to the most recent version. Curl 7.84 <= 8.2.1 Header DoS... in Windows 10 Software and Apps to solve the problem; Hi,I have several servers that have this version of Curl installed. I want to get my servers updated to the most recent version so my questions are:1.... Discussion in 'Windows 10 Software and Apps' started by AD_501, Apr 26, 2024.

  1. AD_501 Win User

    Updating Microsoft Curl to the most recent version. Curl 7.84 <= 8.2.1 Header DoS...


    Hi,I have several servers that have this version of Curl installed. I want to get my servers updated to the most recent version so my questions are:1. What is the best way to get these servers up to the most current version? It seems we are lacking 11 updates since then.2. Could the auto updater failed at one point resulting in these servers not obtaining the proper version?My end goal is to get curl updated to the most current version but I am a little confused on what route to take since we are severely lacking updates. I need this done to resolve a vulnerability found in my environment. Ve

    :)
     
    AD_501, Apr 26, 2024
    #1

  2. Curl Update for Win 11

    Hi,

    The Curl Executable in C:\Windows\System32 (CURL.EXE) is version 7.83.1 which is lower than 7.87.0 and is affeacted by a use-after-free vulnerability.

    Curl can be asked to tunnel virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations.

    When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.

    Referrence:

    curl - HTTP Proxy deny use after free - CVE-2022-43552

    When to expect an offical update from Windows as their is a latest version available on curl for Windows...

    Regards
     
    Rahul Bhichher, Apr 26, 2024
    #2
  3. S Kale Win User
    Curl Arbitrary File Write 7.x >= 7.84.0 / 8.x <= 8.1.2 (CVE-2023-32001) with windows 10 and windows 11

    Hi,

    Nessus found a vulnerability with curl. It looks like Windows 10 and Windows 11 use version 8.0.1 which is vulnerable. (Curl Arbitrary File Write 7.x >= 7.84.0 / 8.x <= 8.1.2 (CVE-2023-32001))

    Does Microsoft plan to release a patch?

    curl - fopen race condition - CVE-2023-32001
     
    S Kale, Apr 26, 2024
    #3
  4. Updating Microsoft Curl to the most recent version. Curl 7.84 <= 8.2.1 Header DoS...

    Update on Patch for Curl

    Yes. As a developer I can tell you that there are live updates for curl on www.github.com most likely under the Microsoft repository.
     
    CatteryDeveloper, Apr 26, 2024
    #4
Thema:

Updating Microsoft Curl to the most recent version. Curl 7.84 <= 8.2.1 Header DoS...

Loading...
  1. Updating Microsoft Curl to the most recent version. Curl 7.84 <= 8.2.1 Header DoS... - Similar Threads - Updating Microsoft Curl

  2. Curl and Libcurl - Vulnerability

    in Windows 10 Software and Apps
    Curl and Libcurl - Vulnerability: Good afternoon! We have reported 3 vulnerabilities in our environment related to the Curl and libcurl versions. Most machines have version 8.10.1.0 in the files located in the paths %windir%\System32\ and %windir%\SysWOW64\. To resolve the vulnerability, it is necessary to...
  3. Curl update Win11 23H2

    in Windows 10 Gaming
    Curl update Win11 23H2: Hello,I am running multiple Windows 11 23H2 and the curl version is still 8.0.1.I have tried installing KB5032190 with no result. The update is not applicable to the affected systems.We use Intune to deploy security patches monthly.Any ideas, besides reinstalling the OS,...
  4. Curl update Win11 23H2

    in Windows 10 Software and Apps
    Curl update Win11 23H2: Hello,I am running multiple Windows 11 23H2 and the curl version is still 8.0.1.I have tried installing KB5032190 with no result. The update is not applicable to the affected systems.We use Intune to deploy security patches monthly.Any ideas, besides reinstalling the OS,...
  5. Updating Microsoft Curl to the most recent version. Curl 7.84 <= 8.2.1 Header DoS...

    in Windows 10 Gaming
    Updating Microsoft Curl to the most recent version. Curl 7.84 <= 8.2.1 Header DoS...: Hi,I have several servers that have this version of Curl installed. I want to get my servers updated to the most recent version so my questions are:1. What is the best way to get these servers up to the most current version? It seems we are lacking 11 updates since then.2....
  6. Updating Microsoft Curl to the most recent version. Curl 7.84 <= 8.2.1 Header DoS...

    in Windows 10 Installation and Upgrade
    Updating Microsoft Curl to the most recent version. Curl 7.84 <= 8.2.1 Header DoS...: Hi,I have several servers that have this version of Curl installed. I want to get my servers updated to the most recent version so my questions are:1. What is the best way to get these servers up to the most current version? It seems we are lacking 11 updates since then.2....
  7. Update on Patch for Curl

    in Windows 10 Gaming
    Update on Patch for Curl: Can I get an update on the fix for CVE-2023-38545 https://answers.microsoft.com/en-us/windows/forum/all/update-on-patch-for-curl/cc17fd5c-cb7c-4e81-add7-edb861330136
  8. Update on Patch for Curl

    in Windows 10 Software and Apps
    Update on Patch for Curl: Can I get an update on the fix for CVE-2023-38545 https://answers.microsoft.com/en-us/windows/forum/all/update-on-patch-for-curl/cc17fd5c-cb7c-4e81-add7-edb861330136
  9. Curl Update for Win 11

    in Windows 10 Gaming
    Curl Update for Win 11: Hi, The Curl Executable in C:\Windows\System32 CURL.EXE is version 7.83.1 which is lower than 7.87.0 and is affeacted by a use-after-free vulnerability. Curl can be asked to tunnel virtually all protocols it supports through an HTTP proxy. HTTP proxies can and often do deny...
  10. Curl Update for Win 11

    in Windows 10 Software and Apps
    Curl Update for Win 11: Hi, The Curl Executable in C:\Windows\System32 CURL.EXE is version 7.83.1 which is lower than 7.87.0 and is affeacted by by a use-after-free vulnerability. Curl can be asked to tunnel virtually all protocols it supports through an HTTP proxy. HTTP proxies can and often do...