PT-2000-1883 · Curl · Curl+1

Published

2000-10-13

·

Updated

2018-05-03

·

CVE-2000-0973

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions curl versions earlier than 6.0-1.1 curl-ssl versions earlier than 6.0-1.2
Description The issue allows remote attackers to execute arbitrary commands by forcing a long error message to be generated when storing an FTP server's error message on failure. This occurs because there is no check for input length, enabling a malicious FTP server to overflow curl's stack-based buffer.
Recommendations For curl versions earlier than 6.0-1.1, update to version 6.0-1.1 or later. For curl-ssl versions earlier than 6.0-1.2, update to version 6.0-1.2 or later.

Exploit

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2000-0973

Affected Products

Curl
Curl-Ssl