[sr-dev] CURL vulnerability

Olle E. Johansson oej at edvina.net
Fri Jan 9 23:02:14 CET 2015


CURL is used in a few parts of Kamailio

http://curl.haxx.se/docs/adv_20150108B.html

THis is a case where a carriage return is embedded into an url. Action C suggest that we make sure
those are stripped out before sending a URL to cURL.

May be an easy fix while waiting for people to upgrade their cURL.

Cheers,
/O


More information about the sr-dev mailing list