* CVE-2021-22922: Wrong content via metalink not discarded
"This was one of the problems we found that that all together made us take the drastic decision to completely remove metalink support.
The metalink format has a hash for the content so that a client can detect faulty contents. curl didn’t act properly if the has mismatched and it could easily make users not realize the bad content."
* CVE-2021-22923: Metalink download sends credentials
"If you download the metalink file using credentials, the subsequent download(s) of the file mentioned in that XML file will also get the same credentials passed to those servers, unexpectedly, thus potentially leaking sensitive information to other parties!
CVE-2021-22924: Bad connection reuse due to flawed path name checks
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse, if one of them matches the setup.
Due to errors in the logic, the config matching function did not take ‘issuer cert’ into account and it compared the involved paths case insensitively, which could lead to libcurl reusing wrong connections!"
* CVE-2021-22925: TELNET stack contents disclosure again
"Possibly the most embarrassing security flaw in a long time.
When we shipped 7.77.0 we announced CVE-2021-22898, which was a flaw in the telnet code and an associated fix. Know what? The fix was incomplete and plain wrong so the original problem actually remained for a certain set of input.
This is thus the second advisory for the same problem and now we fix this again. Hopefully for real and for good this time…"
* CVE-2021-22926: CURLOPT_SSLCERT mixup with Secure Transport
"When libcurl is built to use the macOS native TLS library Secure Transport, an application can ask for the client certificate by name or with a file name – using the same option. If the name exists as a file, it will be used instead of by name. This could be exploited in rare circumstances."
The bug has been referenced in the following commit(s):
Author: Sam James <firstname.lastname@example.org>
AuthorDate: 2021-07-22 02:52:33 +0000
Commit: Sam James <email@example.com>
CommitDate: 2021-07-22 03:20:27 +0000
net-misc/curl: add 7.78.0
* Security bump to 7.78.0
* Drops metalink support (gone upstream entirely)
* Drops two obsolete seds
Signed-off-by: Sam James <firstname.lastname@example.org>
net-misc/curl/Manifest | 1 +
net-misc/curl/curl-7.78.0.ebuild | 289 +++++++++++++++++++++++++++++++++++++++
2 files changed, 290 insertions(+)
(In reply to Sam James from comment #2)
> Let’s go?
Unable to check for sanity:
> no match for package: net-misc/curl-7.78.0
all arches done
Please cleanup, thanks!
(In reply to Sam James from comment #13)
> Please cleanup, thanks!
(In reply to Anthony Basile from comment #14)
> (In reply to Sam James from comment #13)
> > Please cleanup, thanks!
> cleanup done.
Unable to check for sanity:
> no match for package: net-misc/curl-7.78.0-r1