Go to file
Fabian Keil a15342ddc0
wolfssl: plug memory leak in wolfssl_connect_step2()
Fixes:

     test 2034...[simple HTTPS GET with DER public key pinning]
     ==61829== 22,610 (3,744 direct, 18,866 indirect) bytes in 1 blocks are definitely lost in loss record 51 of 54
     ==61829==    at 0x484BB74: malloc (vg_replace_malloc.c:446)
     ==61829==    by 0x4B53A80: wolfSSL_Malloc (memory.c:344)
     ==61829==    by 0x4C1C8E1: wolfSSL_X509_new (x509.c:5326)
     ==61829==    by 0x4C3977D: d2i_X509orX509REQ (x509.c:3628)
     ==61829==    by 0x4C1D1F4: wolfSSL_X509_d2i (x509.c:3664)
     ==61829==    by 0x4C1C37B: wolfSSL_X509_dup (x509.c:13425)
     ==61829==    by 0x4C197DB: wolfSSL_get_peer_certificate (ssl.c:18765)
     ==61829==    by 0x33297C: wolfssl_connect_step2 (wolfssl.c:875)
     ==61829==    by 0x331669: wolfssl_connect_common (wolfssl.c:1287)
     ==61829==    by 0x3303E9: wolfssl_connect_nonblocking (wolfssl.c:1319)
     ==61829==    by 0x32FE89: ssl_connect_nonblocking (vtls.c:510)
     ==61829==    by 0x32DBE5: ssl_cf_connect (vtls.c:1679)
     ==61829==    by 0x27ABD7: Curl_conn_cf_connect (cfilters.c:307)
     ==61829==    by 0x27D9CF: cf_setup_connect (connect.c:1199)
     ==61829==    by 0x27ABD7: Curl_conn_cf_connect (cfilters.c:307)
     ==61829==    by 0x283CEA: cf_hc_baller_connect (cf-https-connect.c:135)

Closes #13272
2024-04-04 08:56:43 +02:00
.circleci CI: Bump the Circle CI base Ubuntu image to the latest 20.04 2024-02-15 16:05:47 -08:00
.github reuse: add copyright + license info to individual docs/*.md files 2024-03-31 12:01:18 +02:00
.reuse reuse: add copyright + license info to individual docs/*.md files 2024-03-31 12:01:18 +02:00
CMake docs: ascii version of manpage without nroff 2024-03-06 15:55:59 +01:00
docs dist: remove the curl-config.1 from the tarball 2024-04-03 13:16:39 +02:00
include RELEASE-NOTES: synced 2024-03-27 12:47:56 +01:00
lib wolfssl: plug memory leak in wolfssl_connect_step2() 2024-04-04 08:56:43 +02:00
LICENSES
m4 m4: reposition USE_RUSTLS="yes" for pkg-config 2024-03-31 23:22:17 +02:00
packages OS400: avoid using awk in the build scripts 2024-02-01 22:31:35 +01:00
plan9
projects GIT-INFO: convert to markdown 2024-03-07 09:43:33 +01:00
scripts maketgz: put docs/RELEASE-TOOL.md into the tarball 2024-03-31 21:27:13 +02:00
src tool_getparam: output warning for leading unicode quote character 2024-03-31 11:59:54 +02:00
tests test1901: verify chunked POST from callback with CURLOPT_POSTFIELDSIZE set 2024-04-02 23:38:35 +02:00
winbuild winbuild: use $(RC) correctly 2024-04-03 14:45:42 +02:00
.azure-pipelines.yml
.cirrus.yml
.dcignore
.dir-locals.el
.git-blame-ignore-revs
.gitattributes
.gitignore
.mailmap
acinclude.m4
appveyor.sh appveyor: OpenSSL 3 no longer found by CMake, revert to 1.1.1 2024-04-03 14:30:55 +00:00
appveyor.yml appveyor: OpenSSL 3 no longer found by CMake, revert to 1.1.1 2024-04-03 14:30:55 +00:00
buildconf
buildconf.bat buildconf.bat: remove outdated groff/nroff use 2024-03-07 22:38:16 +01:00
CHANGES
CMakeLists.txt cmake: enable ENABLE_CURL_MANUAL by default 2024-03-07 09:13:36 +00:00
configure.ac configure: make --disable-docs imply --disable-manual 2024-03-27 12:43:46 +01:00
COPYING
curl-config.in
GIT-INFO.md GIT-INFO: convert to markdown 2024-03-07 09:43:33 +01:00
libcurl.def
libcurl.pc.in
MacOSX-Framework
Makefile.am docs: ascii version of manpage without nroff 2024-03-06 15:55:59 +01:00
Makefile.dist
maketgz maketgz: put docs/RELEASE-TOOL.md into the tarball 2024-03-31 21:27:13 +02:00
README
README.md
RELEASE-NOTES RELEASE-NOTES: synced 2024-03-31 16:35:08 +02:00
SECURITY.md

curl logo

Curl is a command-line tool for transferring data specified with URL syntax. Find out how to use curl by reading the curl.1 man page or the MANUAL document. Find out how to install Curl by reading the INSTALL document.

libcurl is the library curl is using to do its job. It is readily available to be used by your software. Read the libcurl.3 man page to learn how.

You can find answers to the most frequent questions we get in the FAQ document.

Study the COPYING file for distribution terms.

Contact

If you have problems, questions, ideas or suggestions, please contact us by posting to a suitable mailing list.

All contributors to the project are listed in the THANKS document.

Commercial support

For commercial support, maybe private and dedicated help with your problems or applications using (lib)curl visit the support page.

Website

Visit the curl website for the latest news and downloads.

Git

To download the latest source from the Git server, do this:

git clone https://github.com/curl/curl.git

(you will get a directory named curl created, filled with the source code)

Security problems

Report suspected security problems via our HackerOne page and not in public.

Notice

Curl contains pieces of source code that is Copyright (c) 1998, 1999 Kungliga Tekniska Högskolan. This notice is included here to comply with the distribution terms.

Backers

Thank you to all our backers! 🙏 Become a backer.

Sponsors

Support this project by becoming a sponsor.