Curl HTTP/2 Push Headers Memory-leak Vulnerability

Garg, Naman 0 Reputation points
2024-05-16T20:01:49.9966667+00:00

We are receiving vulnerabilities on few VMs related to "Curl HTTP/2 Push Headers Memory-leak" and in solution it is suggested to upgrade to latest Curl (version 8.7.1). But the actual file is in system32 folder and we can't make any changes in that folder because of permission issues.

And, we heared it somewhere that it will be remediated during Windows Update but again, we have installed all Windows Update and failed to remediate the Curl Vulnerability.

Can someone help me to get correct KB as part of which this is being resolved?

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,521 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Michael Taylor 49,261 Reputation points
    2024-05-16T20:11:58.55+00:00

    See this lengthy discussion in the Q&A forums. It includes the links to the information you are asking about. Note that curl.exe will be updated by Windows but any third party apps that use the underlying libcurl (which is where the vulnerability resides) will still need to be updated using whatever update mechanism you use for those apps.


  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more