Aisle Discovers 6 New CVEs in Curl, Including the Oldest Issue Ever Reported
Aisle has discovered 6 new CVEs in the widely used data transfer tool curl, including the oldest-ever reported security issue dating back 24 years. These vulnerabilities affect multiple curl versions and could allow unauthorized data access or denial of service. Users are urged to update to the latest patched versions immediately.
背景メモ
curl(カール)は、ほぼ全てのLinuxやmacOSに標準搭載されている定番のコマンドラインツール。URLを使ってデータ転送を行うためのもので、Webサーバーとの通信やAPI呼び出しなど、ソフトウェア開発・インフラ運用の基盤として広く使われている。
今回、セキュリティ調査会社Aisleがcurlに6件の脆弱性(CVE)を発見。そのうち1件は**24年前**(2000年以前)から存在していたもので、curl史上「最も古くから放置されていたバグ」とされる。curlの開発者は極めて少人数(主要メンテナはDaniel Stenberg氏1人)であり、資金も限られているため、長期間発見されずに眠る脆弱性が出ることがある。