When doing SSH-based transfers using either SCP or SFTP, and setting the knownhosts file, libcurl could still mistakenly accept connecting to hosts not present in the specified file if they were added as recognized in the libssh global knownhosts file.
{
"priority_reason": "This is rated as being low severity by Curl developers",
"binaries": [
{
"binary_version": "7.58.0-2ubuntu3.24+esm7",
"binary_name": "curl"
},
{
"binary_version": "7.58.0-2ubuntu3.24+esm7",
"binary_name": "libcurl3-gnutls"
},
{
"binary_version": "7.58.0-2ubuntu3.24+esm7",
"binary_name": "libcurl3-nss"
},
{
"binary_version": "7.58.0-2ubuntu3.24+esm7",
"binary_name": "libcurl4"
},
{
"binary_version": "7.58.0-2ubuntu3.24+esm7",
"binary_name": "libcurl4-gnutls-dev"
},
{
"binary_version": "7.58.0-2ubuntu3.24+esm7",
"binary_name": "libcurl4-nss-dev"
},
{
"binary_version": "7.58.0-2ubuntu3.24+esm7",
"binary_name": "libcurl4-openssl-dev"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}
{
"priority_reason": "This is rated as being low severity by Curl developers",
"binaries": [
{
"binary_version": "7.68.0-1ubuntu2.25+esm2",
"binary_name": "curl"
},
{
"binary_version": "7.68.0-1ubuntu2.25+esm2",
"binary_name": "libcurl3-gnutls"
},
{
"binary_version": "7.68.0-1ubuntu2.25+esm2",
"binary_name": "libcurl3-nss"
},
{
"binary_version": "7.68.0-1ubuntu2.25+esm2",
"binary_name": "libcurl4"
},
{
"binary_version": "7.68.0-1ubuntu2.25+esm2",
"binary_name": "libcurl4-gnutls-dev"
},
{
"binary_version": "7.68.0-1ubuntu2.25+esm2",
"binary_name": "libcurl4-nss-dev"
},
{
"binary_version": "7.68.0-1ubuntu2.25+esm2",
"binary_name": "libcurl4-openssl-dev"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}
{
"priority_reason": "This is rated as being low severity by Curl developers",
"binaries": [
{
"binary_version": "7.81.0-1ubuntu1.22",
"binary_name": "curl"
},
{
"binary_version": "7.81.0-1ubuntu1.22",
"binary_name": "libcurl3-gnutls"
},
{
"binary_version": "7.81.0-1ubuntu1.22",
"binary_name": "libcurl3-nss"
},
{
"binary_version": "7.81.0-1ubuntu1.22",
"binary_name": "libcurl4"
},
{
"binary_version": "7.81.0-1ubuntu1.22",
"binary_name": "libcurl4-gnutls-dev"
},
{
"binary_version": "7.81.0-1ubuntu1.22",
"binary_name": "libcurl4-nss-dev"
},
{
"binary_version": "7.81.0-1ubuntu1.22",
"binary_name": "libcurl4-openssl-dev"
}
],
"availability": "No subscription required"
}
{
"priority_reason": "This is rated as being low severity by Curl developers",
"binaries": [
{
"binary_version": "8.5.0-2ubuntu10.7",
"binary_name": "curl"
},
{
"binary_version": "8.5.0-2ubuntu10.7",
"binary_name": "libcurl3t64-gnutls"
},
{
"binary_version": "8.5.0-2ubuntu10.7",
"binary_name": "libcurl4-gnutls-dev"
},
{
"binary_version": "8.5.0-2ubuntu10.7",
"binary_name": "libcurl4-openssl-dev"
},
{
"binary_version": "8.5.0-2ubuntu10.7",
"binary_name": "libcurl4t64"
}
],
"availability": "No subscription required"
}