Login Required. Sign up now -- its free!

News


[121 total ]
Adapting to being behind

For many years I’ve always kept up to speed with my commitments in my primary open source projects. I’ve managed to set aside enough time to close the bug reports as fast as they have poured in. This, while stilling having time to work on new features every now and then.
During this last year (or [...]

curl and libcurl 7.19.7

Time again for a happy release event. Can you believe  this is in fact the 113th release?
Run over to the curl download page to get it!
This time, we bring happiness with the best curl and libcurl release ever and it features four changes and a range of bug fixes. The changes to note this time [...]

libcurl in version management

Already before, I’ve mentioned that libcurl is becoming popular within package management.
libcurl is a generic library for file transfers over a wide variety of protocols. Over the years, some of the recent ditributed version management ... [More] softwares have learned about libcurl’s powers and they now use it:
darcs - was born in 2003 and is written in [...] [Less]

How much for a bug?

Warning: blog post with no clear conclusion!
I offer support deals to companies that want to get help with Open Source programs I’ve contributed to. The deals I’ve made so far have primarily involved libcurl, c-ares or libssh2, but that’s basically because those are projects in which I participate a lot in (and maintain) so [...]

Conversing through the Internet with cURL and libcurl

I fell over a really nice and friendly introductionary article on curl and libcurl, written by M. Tim Jones, on IBM’s developerWorks site.
I must confess I greatly enjoyed his image showing the network layers and how curl/libcurl fits into the ... [More] general picture:

While of course arguably there is no ’socket layer’ (as sockets are a pure [...] [Less]

Making better advisories

A while ago yet another security flaw was discovered in curl (actually the tenth flaw in more than eleven years) by Scott Cantor. He reported it privately to us. We worked on the issue and in the end I posted an official project cURL security advisory about it. It wasn’t anything out of the ordinary [...]

50 hours offline

Several sites in the haxx.se domain and other stuff related to me and my fellows were completely offline for almost 50 hours between August 24th 19:00 UTC and August 26th 20:30 UTC.
The sites affected included the main web sites for the following projects: curl, c-ares, trio, libssh2 and Rockbox. It also affected mailing lists and [...]

fully respect your rights

This is [name removed] writing at Toshiba Corporation.
We are considering using your program curl (http://curl.haxx.se/) in our products. Before going any further, however, we would like to confirm the following so that we are sure to fully ... [More] respect your rights.
I am so impressed. Thank you Toshiba for being this upfront and courteous [...] [Less]

curl fooled by null-prefix

We’ve just now released a security advisory on curl and libcurl regarding how a forger can trick libcurl to verify a forged site as having a fine certificate if you just had a CA create one for you with a carefully crafted embedded zero…
I think this flaw brings the light so greatly on the problems [...]

curl 7.19.6 is here!

Yet again we strike back with an update to the popular download tool curl and the transfer library libcurl.
Noticeable changes this time include:

A security related fix, for the flaw named CVE-2009-2417.
CURLOPT_FTPPORT (and curl’s ... [More] -P/–ftpport) support port ranges
Added CURLOPT_SSH_KNOWNHOSTS, CURLOPT_SSH_KEYFUNCTION, CURLOPT_SSH_KEYDATA so that both the library and the curl tool now understand and work with OpenSSH [...] [Less]