Yet again we strike back with an update to the popular download tool curl and the transfer library libcurl.
Noticeable changes this time include:
- A security related fix, for the flaw named CVE-2009-2417.
- CURLOPT_FTPPORT (and curl’s -P/–ftpport) support port ranges
- Added CURLOPT_SSH_KNOWNHOSTS, CURLOPT_SSH_KEYFUNCTION, CURLOPT_SSH_KEYDATA so that both the library and the curl tool now understand and work with OpenSSH style known_hosts file (if built with libssh2 1.2 or later)
- CURLOPT_QUOTE, CURLOPT_POSTQUOTE andÂ CURLOPT_PREQUOTE can be told to ignore error responses when used with FTP. Handy if you want to run custom commands that may fail, but still enjoy persistent connections properly.
Let me just mention that the known_host support will make the SCP and SFTP transfers done with curl one step more secure. My work on this feature (both in libssh2 and in libcurl) was sponsored by a well-known company that shall remain unidentified at their request.