mirror of
https://github.com/moparisthebest/curl
synced 2024-11-05 09:05:04 -05:00
042cc1f69e
(http://curl.haxx.se/docs/adv_20090303.html also known as CVE-2009-0037) in which previous libcurl versions (by design) can be tricked to access an arbitrary local/different file instead of a remote one when CURLOPT_FOLLOWLOCATION is enabled. This flaw is now fixed in this release together this the addition of two new setopt options for controlling this new behavior: o CURLOPT_REDIR_PROTOCOLS controls what protocols libcurl is allowed to follow to when CURLOPT_FOLLOWLOCATION is enabled. By default, this option excludes the FILE and SCP protocols and thus you nee to explicitly allow them in your app if you really want that behavior. o CURLOPT_PROTOCOLS controls what protocol(s) libcurl is allowed to fetch using the primary URL option. This is useful if you want to allow a user or other outsiders control what URL to pass to libcurl and yet not allow all protocols libcurl may have been built to support. |
||
---|---|---|
.. | ||
examples | ||
libcurl | ||
.cvsignore | ||
BINDINGS | ||
BUGS | ||
CONTRIBUTE | ||
curl-config.1 | ||
curl.1 | ||
DISTRO-DILEMMA | ||
FAQ | ||
FEATURES | ||
HISTORY | ||
index.html | ||
INSTALL | ||
INSTALL.devcpp | ||
INTERNALS | ||
KNOWN_BUGS | ||
LICENSE-MIXING | ||
Makefile.am | ||
MANUAL | ||
README.netware | ||
README.win32 | ||
RESOURCES | ||
SSLCERTS | ||
THANKS | ||
TheArtOfHttpScripting | ||
TODO | ||
VERSIONS |
_ _ ____ _ ___| | | | _ \| | / __| | | | |_) | | | (__| |_| | _ <| |___ \___|\___/|_| \_\_____| README.win32 Read the README file first. Curl has been compiled, built and run on all sorts of Windows and win32 systems. While not being the main develop target, a fair share of curl users are win32-based. The unix-style man pages are tricky to read on windows, so therefore are all those pages converted to HTML as well as pdf, and included in the release archives. The main curl.1 man page is also "built-in" in the command line tool. Use a command line similar to this in order to extract a separate text file: curl -M >manual.txt Read the INSTALL file for instructions how to compile curl self.