PT-2000-1883 · Curl · Curl+1
Publicado
2000-10-13
·
Atualizado
2018-05-03
·
CVE-2000-0973
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
curl versions earlier than 6.0-1.1
curl-ssl versions earlier than 6.0-1.2
Description
The issue allows remote attackers to execute arbitrary commands by forcing a long error message to be generated when storing an FTP server's error message on failure. This occurs because there is no check for input length, enabling a malicious FTP server to overflow curl's stack-based buffer.
Recommendations
For curl versions earlier than 6.0-1.1, update to version 6.0-1.1 or later.
For curl-ssl versions earlier than 6.0-1.2, update to version 6.0-1.2 or later.
Exploit
Correção
Stack Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Curl
Curl-Ssl