Home page logo
/

fulldisclosure logo Full Disclosure mailing list archives

cURL/libcURL Arbitrary File Access
From: David Kierznowski <david.kierznowski () gmail com>
Date: Tue, 3 Mar 2009 08:25:14 +0000

cURL/libcURL Arbitrary File Access
Release date: 03/Jan/2009
CVE: CVE-2009-0037

Quote from: http://curl.haxx.se/libcurl/:
"libcurl is a free and easy-to-use client-side URL transfer library,
supporting FTP, FTPS,
HTTP, HTTPS, SCP, SFTP, TFTP, TELNET, DICT, LDAP, LDAPS and FILE."

This vulnerability could permit remote arbitrary file access and command
execution under “less-likely” circumstances.

This is a joint advisory release with cURL. The latest version addresses
this problem.

Full advisory available here:
http://www.withdk.com/2009/03/03/curllibcurl-redirect-arbitrary-file-access/
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

  By Date           By Thread  

Current thread:
  • cURL/libcURL Arbitrary File Access David Kierznowski (Mar 03)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]