﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
1234	Security flaws in cURL 7.13.0 (7.13.1 released)	Dan.Osterrath@…	Randy McMurchy	"There are two security leaks in the current version of cURL.
http://www.idefense.com/application/poi/display?id=202&type=vulnerabilities&flashstatus=false
http://www.idefense.com/application/poi/display?id=203&type=vulnerabilities

iDefense only verified verison 7.12.1 but the cURL news page doesn't state
explicitely that 7.13.0 is clean.
http://curl.haxx.se/news.html

Unfortunately there seems to be only one official patch for the first issue
(NTLM authentication).
http://cool.haxx.se/cvs.cgi/curl/lib/http_ntlm.c.diff?r1=1.36&r2=1.37
The date of revision 1.36 confirms the suspicion that even the current version
is affected.

The second issue (kerberos authentication) seems to be still unpatched. At least
there is a suggestion on the website from iDefense. (see upper links)"	defect	closed	highest		BOOK	SVN	critical	fixed		
