5 Commits

Author SHA256 Message Date
Pedro Monreal
15d8f1566f Update to 8.18.0 2026-01-20 13:52:52 +01:00
16cba07137 Security fixes
* [bsc#1256105, CVE-2025-14017] call ldap_init() before setting the options
* [bsc#1255731, CVE-2025-14524] if redirected, require permission to use bearer
* [bsc#1255734, CVE-2025-15224] require private key or user-agent for public key auth
* [bsc#1255732, CVE-2025-14819] toggling CURLSSLOPT_NO_PARTIALCHAIN makes a different CA cache
* [bsc#1255733, CVE-2025-15079] set both knownhosts options to the same file

Signed-off-by: Lucas Mulling <lucas.mulling@suse.com>
2026-01-07 14:42:10 -03:00
Pedro Monreal
871a7f5ad0 CVE-2025-11563 2025-11-19 16:02:17 +01:00
efd440beb9 Version update and CVE fixes:
- [bsc#1249191, CVE-2025-9086] Out of bounds read for cookie path
 - [bsc#1249348, CVE-2025-10148] Predictable WebSocket mask
2025-10-20 13:16:33 +02:00
747c44eab3 Sync changes to SLFO-1.2 branch 2025-08-20 09:11:02 +02:00

Diff Content Not Available