Comment 3 for bug 1258366

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package curl - 7.27.0-1ubuntu1.6

---------------
curl (7.27.0-1ubuntu1.6) quantal-security; urgency=low

  * SECURITY REGRESSION: can't disable cert checking in command line tool
    (LP: #1258366)
    - debian/patches/CVE-2013-4545.patch: properly disable host
      verification when insecure mode is used in src/tool_operate.c.
    - CVE-2013-4545
 -- Marc Deslauriers <email address hidden> Fri, 06 Dec 2013 07:47:06 -0500