• tony@lemmy.hoyle.me.uk
    link
    fedilink
    arrow-up
    1
    ·
    1 year ago

    They specifically say the high vulnerability one affects the command line tool, not just the library. High implies privilege escalation… I'm wondering how at this point because it's not setuid and there's really no reason opening a TCP socket could cause it (and if it does, that's a kernel error not curl).