[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4136-1 curl -- curl

ID: oval:org.secpod.oval:def:53273Date: (C)2019-04-04   (M)2023-12-20
Class: PATCHFamily: unix




Multiple vulnerabilities were discovered in cURL, an URL transfer library. CVE-2018-1000120 Duy Phan Thanh discovered that curl could be fooled into writing a zero byte out of bounds when curl is told to work on an FTP URL with the setting to only issue a single CWD command, if the directory part of the URL contains a "%00" sequence. CVE-2018-1000121 Dario Weisser discovered that curl might dereference a near-NULL address when getting an LDAP URL due to the ldap_get_attribute_ber fuction returning LDAP_SUCCESS and a NULL pointer. A malicious server might cause libcurl-using applications that allow LDAP URLs, or that allow redirects to LDAP URLs to crash. CVE-2018-1000122 OSS-fuzz, assisted by Max Dymond, discovered that curl could be tricked into copying data beyond the end of its heap based buffer when asked to transfer an RTSP URL.

Platform:
Linux Mint 3
Product:
curl
Reference:
DSA-4136-1
CVE-2018-1000120
CVE-2018-1000121
CVE-2018-1000122
CVE    3
CVE-2018-1000121
CVE-2018-1000122
CVE-2018-1000120
CPE    62
cpe:/a:haxx:curl:7.42.1
cpe:/a:haxx:curl:7.21.0
cpe:/a:haxx:curl:7.42.0
cpe:/a:haxx:curl:7.40.0
...

© SecPod Technologies