Gentoo Linux Security Advisory GLSA 200903-21 – A vulnerability in cURL may allow for arbitrary file access. David Kierznowski reported that the redirect implementation accepts arbitrary Location values when CURLOPT_FOLLOWLOCATION is enabled. Versions less than 7.19.4 are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/75544/glsa-200903-21.txt
Source: https://packetstormsecurity.com/files/75544/Gentoo-Linux-Security-Advisory-200903-21.html

