Questo contenuto non è disponibile nella lingua selezionata.
7.35. curl
7.35.1. RHBA-2013:0393 — curl bug fix update Copia collegamentoCollegamento copiato negli appunti!
Copia collegamentoCollegamento copiato negli appunti!
Updated curl packages that fix several bugs and add various enhancements are now available for Red Hat Enterprise Linux 6.
The curl packages provide the
cURL utility for getting files from HTTP, FTP, FILE, LDAP, LDAPS, DICT, TELNET, and TFTP servers, using any of the supported protocols. This utility offers many useful capabilities, such as proxy support, user authentication, FTP upload, HTTP post, and file transfer resume.
Bug Fixes
- BZ#741935
- The
libssh2library did not sufficiently reflect its ABI extensions in its version, which prevented the RPM dependency scanner from adding the correct dependency oflibcurlon an updated version oflibssh2. Consequently, if the user updatedlibcurlwithout first updatinglibssh2, the update ended with incorrect linkage oflibcurland the user was then unable to updatelibssh2using yum. An explicit dependency oflibcurlon an update version oflibssh2has been added and yum can now be used to updatelibcurl. - BZ#746629
- Previously,
libcurlrequired certificates loaded from files to have unique file base names due to limitation of the legacy API of NSS (Network Security Services). Some packages usinglibcurldid not fulfil this requirement and caused nickname collisions within NSS. Now,libcurlhas been modified to use a newer API of NSS, which does not suffer from this limitation, and packages usinglibcurlare now allowed to load certificates from files with unrestricted file names. - BZ#813127
- Previously,
libcurlmisinterpreted the Content-Length HTTP header when receiving data using the chunked encoding. Consequently,libcurlfailed to read the last chunk of data and the transfer terminated prematurely. An upstream patch has been applied to fix the handling of the header and the chunked encoding inlibcurlnow works as expected. - BZ#841905
- A sub-optimally chosen identifier in cURL source files clashed with an identifier from a public header file introduced in a newer version of
libssh2, which prevented the curl package from a successful build. An upstream patch has been applied on cURL source files, which fixes the identifier collisions and the package now builds as expected. - BZ#738456
- The OpenLDAP suite was recently modified to use NSS instead of OpenSSL as the SSL back end. This change led to collisions between
libcurland OpenLDAP on NSS initialization and shutdown. Consequently, applications that were using bothlibcurland OpenLDAP failed to establish SSL connections. This update modifieslibcurlto use the same NSS API as OpenLDAP, which prevents collisions from occurring. Applications using OpenLDAP andlibcurlcan now connect to the LDAP server over SSL as expected. - BZ#719938
- As a solution to a security issue, GSSAPI credential delegation was disabled, which broke the functionality of applications that were relying on delegation, incorrectly enabled by libcurl. To fix this issue, the
CURLOPT_GSSAPI_DELEGATIONlibcurloption has been introduced in order to enable delegation explicitly when applications need it. All applications using GSSAPI credential delegation can now use this newlibcurloption to be able to run properly. - BZ#772642
- SSL connections could not be established with
libcurlif the selected NSS database was broken or invalid. This update modifies the code oflibcurlto initialize NSS without a valid database, which allows applications to establish SSL connections as expected. - BZ#873789
- Previously,
libcurlincorrectly checked return values of the SCP/SFTP write functions provided bylibssh2. Negative values returned by those functions were treated as negative download amounts, which caused applications to terminate unexpectedly. With this update, all negative values are treated as errors and as such are properly handled on thelibcurllevel, thus preventing the crashes. - BZ#879592
- Prior to this update,
libcurlused an obsoletelibssh2API for uploading files over the SCP protocol, which limited the maximum size of files being transferred on 32-bit architectures. Consequently, the 32-bit packages oflibcurlwere unable to transfer large files over SCP. With this update, a newlibssh2API for SCP uploads is used, which does not suffer from this limitation, thus fixing this bug.
Enhancements
- BZ#676596
- Previously,
libcurlprovided only HTTP status codes in error messages when reporting HTTP errors. This could confuse users not familiar with HTTP. Now,libcurlhas been improved to include the HTTP reason phrase in error messages, thus providing more understandable output. - BZ#730445
- This update introduces a new option,
--delegation, which enables Kerberos credential delegation in cURL.
Users of curl are advised to upgrade to these updated packages, which fix these bugs and add these enhancements.