Nessus Vulnerability - Curl 7.10.5 < 8.12.0 Integer Overflow (CVE-2025-0725)
Damian Crawford (JCAD)
damian at jcad.co.uk
Mon Nov 3 17:26:29 UTC 2025
Hello
Our vulnerability scanning is pick up this vulnerability as a High which we need to action.
Path : c:\program files\shibboleth\sp\lib\curl.exe
Installed version : 8.10.1.0
Fixed version : 8.12.0
Path : c:\program files (x86)\shibboleth\sp\lib\curl.exe
Installed version : 8.10.1.0
Fixed version : 8.12.0
I notice that this version isn't increased in the latest release.
What mitigation errors would you suggest e.g. is it safe to remove this file from the installation or manually replace it with the later version?
Kind regards
Damian
Damian Crawford
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20251103/9c578765/attachment.htm>
More information about the users
mailing list