Updated: curl-7.15.0-3, curl-devel-7.15.0-3, libcurl2-7.11.1-2, libcurl3-7.15.0-3
Sat Nov 26 18:24:00 GMT 2005
I've updated cURL to version 7.15.0.
cURL is a command line tool for transferring files with URL syntax,
supporting FTP, FTPS, TFTP, HTTP, HTTPS, GOPHER, TELNET, DICT, FILE and
LDAP. curl supports HTTPS certificates, HTTP POST, HTTP PUT, FTP
uploading, HTTP form based upload, proxies, cookies, user+password
authentication (Basic, Digest, NTLM, Negotiate, kerberos...), file
transfer resume, proxy tunneling and a busload of other useful tricks.
See <http://curl.haxx.se/> for more information about cURL, and
<http://curl.haxx.se/changes.html> for a list of what has changed.
SSL/TLS support via OpenSSL is enabled in these packages.
IMPORTANT SECURITY INFORMATION:
cURL versions prior to 7.13.1 contain a buffer overflow vulnerability in
the NTLM/krb4 authorization functions. It is strongly recommended that
you upgrade. Note that the updated libcurl2 compatibility package
contains a backport of the fix for this flaw, so it is safe to use.
The layout of the curl packages has been changed, with the DLL moved to
its own versioned package, as follows:
curl: main curl command line binary and documentation
libcurl3: current version of the libcurl runtime (DLL)
libcurl2: older obsolete version of the libcurl runtime (DLL)
curl-devel: headers, static library, import library, samples, and
documentation for developing applications that use libcurl
libcurl2 exists only to provide the older version of the DLL for
existing programs that were linked to libcurl -- currently this is only
ogg123 from the vorbis-tools package, and any third party or
self-compiled apps. All new applications should use libcurl3.
Version 7.11.1-1 of curl is still available as "prev". However, please
do note that you *must* manually select libcurl2 *and* ensure that its
cygcurl-2.dll overwrites the old vulnerable cygcurl-2.dll in the old
7.11.1 package if you plan to use this version, otherwise you will still
be vulnerable to the above security flaw.
To update your installation, click on the "Install Cygwin now" link on
the http://cygwin.com/ web page. This downloads setup.exe to your
system. Then, run setup and answer all of the questions.
*** CYGWIN-ANNOUNCE UNSUBSCRIBE INFO ***
If you want to unsubscribe from the cygwin-announce mailing list, look
at the "List-Unsubscribe: " tag in the email header of this message.
Send email to the address specified there. It will be in the format:
If you need more information on unsubscribing, start reading here:
Please read *all* of the information on unsubscribing that is available
starting at this URL.
More information about the Cygwin-announce