Vulnerability CVE-2024-7264 in `libcurl.dll` – When Will It Be Addressed in Notepad++?
-
Hi all,
I recently updated Notepad++ to the latest version, hoping it would resolve the vulnerability in
libcurl.dll
(CVE-2024-7264), which affects versions >= 7.32.0, < 8.9.1. However, after the update, I checked thelibcurl.dll
version in theC:\Program Files (x86)\Notepad++\updater\libcurl.dll
path, and it still shows version 8.4.0, which remains vulnerable.Is there any planned release that will include
libcurl
version 8.9.1 or higher to fix this vulnerability? Or should I manually update thelibcurl.dll
file? Any guidance would be appreciated.Thanks!
-
Do you think you get better answers if you post the same thing 3 times??
-
-
Future readers: this query was answered here and here, which both point to https://github.com/notepad-plus-plus/wingup/issues/73#issuecomment-2362168716 as the official answer.
This duplicate request locked. Discussion can continue in the first link above.