💾 IT Security Tools 🕛 vor 1 Monat 1 Min Lesezeit SECURITY-FEED
0

GitHub: backup/38320-pre-rebase4-20260813: fix: point DEPS_VERSION at the bundle carrying the OpenSSL curl

↗ Quelle (GitHub · github.com)
🗣️ Stimme:
🐙
$ git clone https://github.com/wazuh/wazuh.git

Building curl with --with-openssl only changes the product if the agent build

actually compiles curl, and it does not: make deps pulls a precompiled

archive and the CMake short-circuits on it, which is the path

5_builderpackage_agent-windows.yml uses. Against 99-37702 the winagent kept

getting the Schannel curl built on 2026-05-19, so the flag was inert

everywhere except a local EXTERNAL_SRC_ONLY=yes build.


99-38163 is the first bundle built from this branch, so its windows curl

reports USE_OPENSSL. Verified by the default path -- no EXTERNAL_SRC_ONLY,

curl not recompiled:


external/curl/lib/curl_config.h

#define USE_OPENSSL 1

/* #undef USE_SCHANNEL */


and the agent built from it reaches a TLS 1.3-only manager from Windows 10,

where the github and office365 modules still validate against the machine's

certificate stores.

Vollständiges Original-Advisory
Ausführliche Details, Exploit-Analyse & Hersteller-Stellungnahme auf github.com.
↗ Original-Artikel auf github.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
6 Quellen
CVE-2022-44255 | TOTOLINK LR350 9.3.5u.6369_B20220309 buffer overflow (EUVD-2022-47204)
2 Quellen
CVE-2026-68426 | Linux Kernel up to 6.18.41/7.1.5/7.2-rc3 xfrm validate_xmit_skb_list use after free (Nessus ID 346426)
1 Quelle
Windows 11 Probleme mit gültiger Domänenanmeldung nach September-Update [Workaround]