
Full Disclosure mailing list archives
cURL/libcURL Arbitrary File Access
From: David Kierznowski <david.kierznowski () gmail com>
Date: Tue, 3 Mar 2009 08:25:14 +0000
cURL/libcURL Arbitrary File Access Release date: 03/Jan/2009 CVE: CVE-2009-0037 Quote from: http://curl.haxx.se/libcurl/: "libcurl is a free and easy-to-use client-side URL transfer library, supporting FTP, FTPS, HTTP, HTTPS, SCP, SFTP, TFTP, TELNET, DICT, LDAP, LDAPS and FILE." This vulnerability could permit remote arbitrary file access and command execution under “less-likely” circumstances. This is a joint advisory release with cURL. The latest version addresses this problem. Full advisory available here: http://www.withdk.com/2009/03/03/curllibcurl-redirect-arbitrary-file-access/
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- cURL/libcURL Arbitrary File Access David Kierznowski (Mar 03)