Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

Mageia 9 Security Advisory MGASA-2025-0123: curl Password Leak Issue

mageia
Calendar Grey April 3, 2025
Dist Mageia Esm H88
Essential Mageia patch resolves credential exposure in curl. Corrects various security flaws for enhanced protection.
When asked to use a .netrc file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstanc...

Summary

When asked to use a .netrc file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. The fix was included previously as part of MGAA-2025-0004.

References

- https://bugs.mageia.org/show_bug.cgi?id=33992

- https://bugs.mageia.org/show_bug.cgi?id=33893

- https://curl.se/docs/CVE-2025-0167.html

- https://advisories.mageia.org/MGAA-2025-0004.html

- https://www.cve.org/CVERecord?id=CVE-2025-0167

- https://www.cve.org/CVERecord?id=CVE-2025-0665

- https://www.cve.org/CVERecord?id=CVE-2025-0725

Resolution

SRPMS

- 9/core/curl-7.88.1-4.6.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 03 Apr 2025
URL: https://advisories.mageia.org/MGASA-2025-0123.html
Type: security
CVE: CVE-2025-0167, CVE-2025-0665, CVE-2025-0725

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here