When asked to use a .netrc file for credentials and to follow HTTP
redirects, curl could leak the password used for the first host to the
followed-to host under certain circumstances. The fix was included
previously as part of MGAA-2025-0004.
- https://bugs.mageia.org/show_bug.cgi?id=33992
- https://bugs.mageia.org/show_bug.cgi?id=33893
- https://curl.se/docs/CVE-2025-0167.html
- https://advisories.mageia.org/MGAA-2025-0004.html
- https://www.cve.org/CVERecord?id=CVE-2025-0167
- https://www.cve.org/CVERecord?id=CVE-2025-0665
- https://www.cve.org/CVERecord?id=CVE-2025-0725
- 9/core/curl-7.88.1-4.6.mga9
Get the latest Linux and open source security news straight to your inbox.