| Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search | 
| Name: libcurl-minimal | Distribution: Fedora Project | 
| Version: 8.9.1 | Vendor: Fedora Project | 
| Release: 4.fc41 | Build date: Wed Sep 17 15:05:05 2025 | 
| Group: Unspecified | Build host: buildvm-s390x-15.s390.fedoraproject.org | 
| Size: 695814 | Source RPM: curl-8.9.1-4.fc41.src.rpm | 
| Packager: Fedora Project | |
| Url: https://curl.se/ | |
| Summary: Conservatively configured build of libcurl for minimal installations | |
This is a replacement of the 'libcurl' package for minimal installations. It comes with a limited set of features compared to the 'libcurl' package. On the other hand, the package is smaller and requires fewer run-time dependencies to be installed.
curl
* Wed Sep 17 2025 Jan Macku <jamacku@redhat.com> - 8.9.1-4
  - fix Out of bounds read for cookie path (CVE-2025-9086)
* Thu Dec 12 2024 Jan Macku <jamacku@redhat.com> - 8.9.1-3
  - fix HSTS subdomain overwrites parent cache entry (CVE-2024-9681)
* Mon Aug 05 2024 voidanix <voidanix@keyedlimepie.org> - 8.9.1-2
  - Apply SIGPIPE-related patch due to upstream regression
* Wed Jul 24 2024 Jan Macku <jamacku@redhat.com> - 8.9.1-1
  - new upstream release
* Wed Jul 24 2024 Jan Macku <jamacku@redhat.com> - 8.9.0-1
  - new upstream release, which fixes the following vulnerabilities
      CVE-2024-6874 - macidn punycode buffer overread
      CVE-2024-6197 - freeing stack buffer in utf8asn1str
  - drop upstreamed patches
* Wed Jul 17 2024 Fedora Release Engineering <releng@fedoraproject.org> - 8.8.0-3
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Fri Jul 12 2024 Paul Howarth <paul@city-fan.org> - 8.8.0-2
  - adapt for https://fedoraproject.org/wiki/Changes/OpensslDeprecateEngine
  - added build condition for openssl_engine_support, true by default so as to
    not change the resulting built package (yet)
  - with openssl_engine_support true, BR: openssl-devel-engine
  - with openssl_engine_support false, build with -DOPENSSL_NO_ENGINE
* Wed May 22 2024 Jan Macku <jamacku@redhat.com> - 8.8.0-1
  - new upstream release
  - drop upstreamed patches
* Wed Mar 27 2024 Jan Macku <jamacku@redhat.com> - 8.7.1-1
  - new upstream release, which fixes the following vulnerabilities
      CVE-2024-2004 - Usage of disabled protocol
      CVE-2024-2379 - QUIC certificate check bypass with wolfSSL
      CVE-2024-2398 - HTTP/2 push headers memory-leak
      CVE-2024-2466 - TLS certificate check bypass with mbedTLS
  - drop upstreamed patches
  - reenable test 0313
  - fix zsh completions, use --with-zsh-functions-dir
  - apply upstream patches for 8.7.1 issues and regressions
* Mon Feb 19 2024 Jan Macku <jamacku@redhat.com> - 8.6.0-7
  - Fix: Leftovers after chunking should not be part of the curl buffer output (#2264220)
* Mon Feb 12 2024 Jan Macku <jamacku@redhat.com> - 8.6.0-6
  - revert "receive max buffer" + add test case
  - temporarily disable test 0313
  - remove suggests of libcurl-minimal in curl-full
* Mon Feb 12 2024 Jan Macku <jamacku@redhat.com> - 8.6.0-5
  - add Provides to curl-minimal
* Wed Feb 07 2024 Jan Macku <jamacku@redhat.com> - 8.6.0-4
  - drop curl-minimal subpackage in favor of curl-full (#2262096)
* Mon Feb 05 2024 Jan Macku <jamacku@redhat.com> - 8.6.0-3
  - ignore response body to HEAD requests
* Fri Feb 02 2024 Jan Macku <jamacku@redhat.com> - 8.6.0-2
  - don't build manual for curl-full - use man 1 curl instead (#2262373)
* Thu Feb 01 2024 Jan Macku <jamacku@redhat.com> - 8.6.0-1
  - new upstream release, which fixes the following vulnerabilities
      CVE-2024-0853 - OCSP verification bypass with TLS session reuse
  - drop 001-dist-add-tests-errorcodes.pl-to-the-tarball.patch (replaced by upstream fix)
  - remove accidentally included mk-ca-bundle.1 man page (upstream bug #12843)
* Fri Jan 19 2024 Fedora Release Engineering <releng@fedoraproject.org> - 8.5.0-2
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Wed Dec 06 2023 Jan Macku <jamacku@redhat.com> - 8.5.0-1
  - new upstream release, which fixes the following vulnerabilities
      CVE-2023-46218 - cookie mixed case PSL bypass
      CVE-2023-46219 - HSTS long file name clears contents
* Wed Oct 11 2023 Jan Macku <jamacku@redhat.com> - 8.4.0-1
  - new upstream release, which fixes the following vulnerabilities
      CVE-2023-38545 - SOCKS5 heap buffer overflow
      CVE-2023-38546 - cookie injection with none file
/usr/lib/.build-id /usr/lib/.build-id/77 /usr/lib/.build-id/77/d5202f09b6e14a251d97e01fb299f5c5420d59 /usr/lib64/libcurl.so.4 /usr/lib64/libcurl.so.4.8.0 /usr/share/licenses/libcurl-minimal /usr/share/licenses/libcurl-minimal/COPYING
Generated by rpm2html 1.8.1
Fabrice Bellet, Fri Oct 31 07:02:05 2025