Debian Security Advisory

DLA-134-1 curl -- LTS security update

Date Reported:
15 Jan 2015
Affected Packages:
Security database references:
In Mitre's CVE dictionary: CVE-2014-8150.
More information:

Andrey Labunets of Facebook discovered that cURL, an URL transfer library, fails to properly handle URLs with embedded end-of-line characters. An attacker able to make an application using libcurl to access a specially crafted URL via an HTTP proxy could use this flaw to do additional requests in a way that was not intended, or insert additional request headers into the request.

For Debian 6 Squeeze, these issues have been fixed in curl version 7.21.0-2.1+squeeze11