Пакет curl: Информация

    Исходный пакет: curl
    Версия: 8.21.0-alt1
    Собран:  25 июня 2026 г. 13:26
    Сообщить об ошибке в пакете
    Домашняя страница: https://curl.se/

    Лицензия: curl
    О пакете: Gets a file from a FTP, GOPHER or HTTP server
    Описание: 
    Curl is a client to get documents/files from servers, using any of the
    supported protocols. The command is designed to work without user
    interaction or any kind of interactivity.
    
    Curl offers a busload of useful tricks like proxy support, user
    authentication, ftp upload, HTTP post, file transfer resume and more.

    Список бинарных RPM-пакетов, собираемых из данного SRPM:
    curl (loongarch64)
    curl-debuginfo (loongarch64)
    libcurl (loongarch64)
    libcurl-debuginfo (loongarch64)
    libcurl-devel (loongarch64)

    Сопровождающий: Anton Farygin


      1. /proc
      2. /usr/bin/stunnel
      3. apache2-devel
      4. apache2-httpd-worker
      5. apache2-mod_http2
      6. apache2-mod_ssl
      7. caddy
      8. gnutls-utils
      9. groff-base
      10. libbrotli-devel
      11. libgnutls-devel
      12. libgnutls30
      13. libgsasl-devel
      14. libidn2-devel
      15. libkrb5-devel
      16. libldap-devel
      17. libnettle-devel
      18. libnghttp2-devel
      19. libnghttp2-tools
      20. libnghttp3-devel
      21. libngtcp2-devel >= 0.15.0
      22. libpsl-devel
      23. libssh2-devel
      24. libzstd-devel
      25. openssh-clients
      26. openssh-server
      27. perl(Digest/SHA.pm)
      28. perl(Memoize.pm)
      29. pytest3
      30. python3-base
      31. python3-module-cryptography
      32. python3-module-filelock
      33. python3-module-psutil
      34. python3-module-pytest-xdist
      35. vsftpd
      36. zlib-devel

    Последнее изменение


    24 июня 2026 г. Anton Farygin 8.21.0-alt1
    - 8.20.0 -> 8.21.0
    - Fixes:
      * CVE-2026-12064: proto-default skips SSH verification
      * CVE-2026-11856: cross-origin Digest auth state leak
      * CVE-2026-11586: WS Auto-PONG memory exhaustion
      * CVE-2026-11564: Native CA trust persist
      * CVE-2026-11352: QUIC zero-length UDP datagrams busy-loop
      * CVE-2026-10536: HTTP/2 stream-dependency tree UAF
      * CVE-2026-9547: SSH improper host validation
      * CVE-2026-9546: sending old referer
      * CVE-2026-9545: exposing HTTP/3 early data
      * CVE-2026-9080: UAF after pause in socket callback
      * CVE-2026-9079: stale proxy password leak
      * CVE-2026-8932: incomplete mTLS config matching in conn reuse
      * CVE-2026-8927: env-set cross-proxy Digest auth state leak
      * CVE-2026-8926: password leak with netrc and user in URL
      * CVE-2026-8925: SASL double-free
      * CVE-2026-8924: trailing dot domain super cookie
      * CVE-2026-8458: wrong reuse for different services
      * CVE-2026-8286: wrong STARTTLS connection reuse
    29 апреля 2026 г. Anton Farygin 8.20.0-alt1
    - 8.19.0 -> 8.20.0
    - Fixes:
      * CVE-2026-7168: cross-proxy Digest auth state leak
      * CVE-2026-7009: OCSP stapling bypass with Apple SecTrust
      * CVE-2026-6429: netrc credential leak with reused proxy connection
      * CVE-2026-6276: stale custom cookie host causes cookie leak
      * CVE-2026-6253: proxy credentials leak over redirect-to proxy
      * CVE-2026-5773: wrong reuse of SMB connection
      * CVE-2026-5545: wrong reuse of HTTP Negotiate connection
      * CVE-2026-4873: connection reuse ignores TLS requirement
    11 марта 2026 г. Anton Farygin 8.19.0-alt1
    - 8.18.0 -> 8.19.0
    - Fixes:
      * CVE-2026-3805: use after free in SMB connection reuse
      * CVE-2026-3784: wrong proxy connection reuse with credentials
      * CVE-2026-3783: token leak with redirect and netrc
      * CVE-2026-1965: bad reuse of HTTP Negotiate connection