PT-2000-1883 · Curl · Curl+1

Publicado

2000-10-13

·

Atualizado

2018-05-03

·

CVE-2000-0973

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions curl versions earlier than 6.0-1.1 curl-ssl versions earlier than 6.0-1.2
Description The issue allows remote attackers to execute arbitrary commands by forcing a long error message to be generated when storing an FTP server's error message on failure. This occurs because there is no check for input length, enabling a malicious FTP server to overflow curl's stack-based buffer.
Recommendations For curl versions earlier than 6.0-1.1, update to version 6.0-1.1 or later. For curl-ssl versions earlier than 6.0-1.2, update to version 6.0-1.2 or later.

Exploit

Correção

Stack Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2000-0973

Produtos afetados

Curl
Curl-Ssl