Multiple stack-based buffer overflows in libcURL and cURL 7.12.1, and possibly other versions, allow remote malicious web servers to execute arbitrary code via base64 encoded replies that exceed the intended buffer lengths when decoded, which is not properly handled by (1) the Curl_input_ntlm function in http_ntlm.c during NTLM authentication or (2) the Curl_krb_kauth and krb4_auth functions in krb4.c during Kerberos authentication.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:55
Type | Values Removed | Values Added |
---|---|---|
References | () http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000940 - Broken Link, Patch, Vendor Advisory | |
References | () http://marc.info/?l=full-disclosure&m=110959085507755&w=2 - Mailing List, Patch | |
References | () http://www.gentoo.org/security/en/glsa/glsa-200503-20.xml - Third Party Advisory | |
References | () http://www.idefense.com/application/poi/display?id=202&type=vulnerabilities - Broken Link, Vendor Advisory | |
References | () http://www.idefense.com/application/poi/display?id=203&type=vulnerabilities - Broken Link, Vendor Advisory | |
References | () http://www.mandriva.com/security/advisories?name=MDKSA-2005:048 - Third Party Advisory | |
References | () http://www.novell.com/linux/security/advisories/2005_11_curl.html - Broken Link | |
References | () http://www.redhat.com/support/errata/RHSA-2005-340.html - Broken Link | |
References | () http://www.securityfocus.com/bid/12615 - Broken Link, Third Party Advisory, VDB Entry | |
References | () http://www.securityfocus.com/bid/12616 - Broken Link, Third Party Advisory, VDB Entry | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/19423 - Third Party Advisory, VDB Entry | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10273 - Broken Link |
02 Feb 2024, 03:05
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-131 | |
First Time |
Haxx libcurl
Haxx curl Haxx |
|
References | (MANDRAKE) http://www.mandriva.com/security/advisories?name=MDKSA-2005:048 - Third Party Advisory | |
References | (GENTOO) http://www.gentoo.org/security/en/glsa/glsa-200503-20.xml - Third Party Advisory | |
References | (CONECTIVA) http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000940 - Broken Link, Patch, Vendor Advisory | |
References | (SUSE) http://www.novell.com/linux/security/advisories/2005_11_curl.html - Broken Link | |
References | (OVAL) https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10273 - Broken Link | |
References | (REDHAT) http://www.redhat.com/support/errata/RHSA-2005-340.html - Broken Link | |
References | (BID) http://www.securityfocus.com/bid/12616 - Broken Link, Third Party Advisory, VDB Entry | |
References | (BID) http://www.securityfocus.com/bid/12615 - Broken Link, Third Party Advisory, VDB Entry | |
References | (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/19423 - Third Party Advisory, VDB Entry | |
References | (FULLDISC) http://marc.info/?l=full-disclosure&m=110959085507755&w=2 - Mailing List, Patch | |
References | (IDEFENSE) http://www.idefense.com/application/poi/display?id=203&type=vulnerabilities - Broken Link, Vendor Advisory | |
References | (IDEFENSE) http://www.idefense.com/application/poi/display?id=202&type=vulnerabilities - Broken Link, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : 5.1
v3 : 8.8 |
CPE | cpe:2.3:a:libcurl:libcurl:7.12.1:*:*:*:*:*:*:* |
cpe:2.3:a:haxx:libcurl:7.12.1:*:*:*:*:*:*:* cpe:2.3:a:haxx:curl:7.12.1:*:*:*:*:*:*:* |
Information
Published : 2005-05-02 04:00
Updated : 2024-11-20 23:55
NVD link : CVE-2005-0490
Mitre link : CVE-2005-0490
CVE.ORG link : CVE-2005-0490
JSON object : View
Products Affected
haxx
- curl
- libcurl
CWE
CWE-131
Incorrect Calculation of Buffer Size