Hi,

The libidn issue that was previously reported[1], is still outstanding and hasn't been fixed in libidn. This keeps wget vulnerable.

I've just recommended[2] libcurl users to disable libidn until this gets resolved, as it seems it may drag on and keeping vulnerable code around is not good.

[1] = https://lists.gnu.org/archive/html/bug-wget/2015-06/msg00002.html
[2] = http://curl.haxx.se/mail/lib-2015-06/0143.html

--

 / daniel.haxx.se

Reply via email to