1824Fermer1826
ZerosquareLe 20/10/2021 à 20:44
https://seclists.org/fulldisclosure/2021/Oct/17 :
in December 2017, Microsoft announced to ship curl.exe and tar.exe with Windows 10:

But they failed once again, MISERABLY, at least for curl: they took the sources released 2017-11-14, let them rot for 2 years, applied some patches, only to let them rot again since then!

C:\Users\Public>winver
Microsoft Windows [Version 10.0.19042.1083]

C:\Users\Public>curl -V
curl 7.55.1 (Windows) libcurl/7.55.1 WinSSL
Release-Date: 2017-11-14, security patched: 2019-11-05
Protocols: dict file ftp ftps http https imap imaps pop3 pop3s smtp smtps telnet tftp
Features: AsynchDNS IPv6 Largefile SSPI Kerberos SPNEGO NTLM SSL
Version 7.55.1 is 34 releases and at least 15 (in words: FIFTEEN) CVEs behind the current version 7.79.1: see https://curl.se/docs/releases.html and https://curl.se/docs/vulnerabilities.html