1. 18 May, 2009 1 commit
  2. 11 May, 2009 5 commits
  3. 08 May, 2009 1 commit
  4. 07 May, 2009 1 commit
  5. 04 May, 2009 3 commits
  6. 03 May, 2009 1 commit
  7. 01 May, 2009 1 commit
  8. 30 Apr, 2009 3 commits
  9. 29 Apr, 2009 1 commit
  10. 28 Apr, 2009 1 commit
    • Daniel Stenberg's avatar
      - Bug report #2709004 (http://curl.haxx.se/bug/view.cgi?id=2709004) by Tim · e01b7c1e
      Daniel Stenberg authored
        Chen pointed out how curl couldn't upload with resume when reading from a
        pipe.
      
        This ended up with the introduction of a new return code for the
        CURLOPT_SEEKFUNCTION callback that basically says that the seek failed but
        that libcurl may try to resolve the situation anyway. In our case this means
        libcurl will attempt to instead read that much data from the stream instead
        of seeking and that way curl can now upload with resume when data is read
        from a stream!
      e01b7c1e
  11. 27 Apr, 2009 1 commit
  12. 23 Apr, 2009 2 commits
  13. 18 Apr, 2009 3 commits
  14. 17 Apr, 2009 1 commit
  15. 07 Apr, 2009 1 commit
  16. 06 Apr, 2009 1 commit
  17. 20 Mar, 2009 1 commit
  18. 18 Mar, 2009 2 commits
  19. 05 Mar, 2009 1 commit
  20. 03 Mar, 2009 1 commit
  21. 02 Mar, 2009 2 commits
    • Daniel Stenberg's avatar
      - David Kierznowski notified us about a security flaw · 042cc1f6
      Daniel Stenberg authored
        (http://curl.haxx.se/docs/adv_20090303.html also known as CVE-2009-0037) in
        which previous libcurl versions (by design) can be tricked to access an
        arbitrary local/different file instead of a remote one when
        CURLOPT_FOLLOWLOCATION is enabled. This flaw is now fixed in this release
        together this the addition of two new setopt options for controlling this
        new behavior:
      
        o CURLOPT_REDIR_PROTOCOLS controls what protocols libcurl is allowed to
        follow to when CURLOPT_FOLLOWLOCATION is enabled. By default, this option
        excludes the FILE and SCP protocols and thus you nee to explicitly allow
        them in your app if you really want that behavior.
      
        o CURLOPT_PROTOCOLS controls what protocol(s) libcurl is allowed to fetch
        using the primary URL option. This is useful if you want to allow a user or
        other outsiders control what URL to pass to libcurl and yet not allow all
        protocols libcurl may have been built to support.
      curl-7_19_4
      042cc1f6
    • Daniel Stenberg's avatar
      the Eiffel binding · 4bc603a0
      Daniel Stenberg authored
      4bc603a0
  22. 27 Feb, 2009 1 commit
  23. 23 Feb, 2009 4 commits
  24. 20 Feb, 2009 1 commit