Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Mageia 9 Security Advisory MGASA-2025-0123: curl Password Leak Issue

mageia
Calendar Grey April 3, 2025
Scroller Mageia
Essential Mageia patch resolves credential exposure in curl. Corrects various security flaws for enhanced protection.
When asked to use a .netrc file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstanc...

Summary

When asked to use a .netrc file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. The fix was included previously as part of MGAA-2025-0004.

References

- https://bugs.mageia.org/show_bug.cgi?id=33992

- https://bugs.mageia.org/show_bug.cgi?id=33893

- https://curl.se/docs/CVE-2025-0167.html

- https://advisories.mageia.org/MGAA-2025-0004.html

- https://www.cve.org/CVERecord?id=CVE-2025-0167

- https://www.cve.org/CVERecord?id=CVE-2025-0665

- https://www.cve.org/CVERecord?id=CVE-2025-0725

Resolution

SRPMS

- 9/core/curl-7.88.1-4.6.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 03 Apr 2025
URL: https://advisories.mageia.org/MGASA-2025-0123.html
Type: security
CVE: CVE-2025-0167, CVE-2025-0665, CVE-2025-0725

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.