CVE-2009-2417 by Fred · 14/08/2009 lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a ‘