PT-2005-1058 · Curl+2 · Libcurl+3

Publicado

2005-10-13

·

Atualizado

2018-10-03

·

CVE-2005-3185

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions wget version 1.10 curl versions prior to 7.15.0 libcurl versions prior to 7.15.0
Description The issue is related to a stack-based buffer overflow in the ntlm output function when NTLM authentication is enabled, allowing remote servers to execute arbitrary code via a long NTLM username. This can lead to a violation of confidentiality, integrity, and availability of protected information. The exploitation can be carried out remotely.
Recommendations For wget version 1.10, update to a version that fixes the NTLM authentication issue. For curl versions prior to 7.15.0, update to version 7.15.0 or later to fix the buffer overflow vulnerability. For libcurl versions prior to 7.15.0, update to version 7.15.0 or later to fix the buffer overflow vulnerability. As a temporary workaround, consider disabling NTLM authentication until a patch is available. Avoid using username and domain name combinations longer than 192 bytes when NTLM authentication is enabled.

Correção

Buffer Overflow

Stack Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-04811
BDU:2015-09482
CVE-2005-3185
DSA-919-2
RHSA-2005:812
RHSA-2005_807
RHSA-2005_812

Produtos afetados

Red Hat
Curl
Libcurl
Wget