1. 02 Mar, 2009 3 commits
    • Daniel Stenberg's avatar
      - David Kierznowski notified us about a security flaw · 042cc1f6
      Daniel Stenberg authored
        (http://curl.haxx.se/docs/adv_20090303.html also known as CVE-2009-0037) in
        which previous libcurl versions (by design) can be tricked to access an
        arbitrary local/different file instead of a remote one when
        CURLOPT_FOLLOWLOCATION is enabled. This flaw is now fixed in this release
        together this the addition of two new setopt options for controlling this
        new behavior:
      
        o CURLOPT_REDIR_PROTOCOLS controls what protocols libcurl is allowed to
        follow to when CURLOPT_FOLLOWLOCATION is enabled. By default, this option
        excludes the FILE and SCP protocols and thus you nee to explicitly allow
        them in your app if you really want that behavior.
      
        o CURLOPT_PROTOCOLS controls what protocol(s) libcurl is allowed to fetch
        using the primary URL option. This is useful if you want to allow a user or
        other outsiders control what URL to pass to libcurl and yet not allow all
        protocols libcurl may have been built to support.
      curl-7_19_4
      042cc1f6
    • Daniel Stenberg's avatar
      7.19.4 won't get anything else · 90b804d3
      Daniel Stenberg authored
      90b804d3
    • Daniel Stenberg's avatar
      the Eiffel binding · 4bc603a0
      Daniel Stenberg authored
      4bc603a0
  2. 01 Mar, 2009 1 commit
  3. 28 Feb, 2009 2 commits
  4. 27 Feb, 2009 4 commits
  5. 25 Feb, 2009 2 commits
  6. 24 Feb, 2009 3 commits
  7. 23 Feb, 2009 9 commits
  8. 20 Feb, 2009 6 commits
  9. 19 Feb, 2009 3 commits
  10. 18 Feb, 2009 2 commits
  11. 17 Feb, 2009 5 commits