PT-2016-6149 · Curl+1 · Libcurl+1

Guohui

·

Publicado

2016-05-30

·

Atualizado

2016-12-31

·

CVE-2016-4802

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions libcurl versions prior to 7.49.1
Description The issue allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse in the application or current working directory. This is due to libcurl loading Windows system DLLs in a manner that makes it vulnerable to a DLL hijacking attack in certain configurations. The DLLs security.dll, secur32.dll, and ws2 32.dll may be loaded dynamically, and an attacker may plant a DLL of the same name in the user's current directory, application directory, or other directory in the DLL search order. Recent versions of Windows include all three of these dynamically loaded system DLLs and enable safe DLL search mode by default, which limits the attack vector. To mitigate this, it is advised to guard write permissions on the application directory.
Recommendations For versions prior to 7.49.1, update to version 7.49.1 or later to address the issue. As a temporary workaround, consider restricting write access to the application directory to prevent DLL planting attacks. Additionally, avoid using the LoadLibrary() function without specifying a path for the DLLs security.dll, secur32.dll, and ws2 32.dll until the issue is resolved.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1560
CVE-2016-4802

Produtos afetados

Alt Linux
Libcurl