Re: [lftp] lftp is affected by curl CVE-2014-0139

2015-02-10 Thread Vitezslav Cizek
Hi Alexander, * Dne Úterý 10. únor 2015, 13:25:03 [CET] Alexander V. Lukyanov napsal: > On Tue, Dec 09, 2014 at 06:46:32PM +0100, Vitezslav Cizek wrote: > > Hi, > > I've noticed lftp is using code borrowed from curl. > > That makes lftp affected by CVE-2014-0139: > > http://curl.haxx.se/docs/adv_20

Re: [lftp] lftp is affected by curl CVE-2014-0139

2015-02-10 Thread Alexander V. Lukyanov
On Tue, Dec 09, 2014 at 06:46:32PM +0100, Vitezslav Cizek wrote: > Hi, > I've noticed lftp is using code borrowed from curl. > That makes lftp affected by CVE-2014-0139: > http://curl.haxx.se/docs/adv_20140326B.html > > It's not the most critical vulnerability, but anyway, > I'll suggest to update

[lftp] lftp is affected by curl CVE-2014-0139

2015-02-10 Thread Vitezslav Cizek
Hi, I've noticed lftp is using code borrowed from curl. That makes lftp affected by CVE-2014-0139: http://curl.haxx.se/docs/adv_20140326B.html It's not the most critical vulnerability, but anyway, I'll suggest to update to code from latest curl for the next release. -- Vita Cizek signature.asc