Lucene search

K
cve[email protected]CVE-2009-0037
HistoryMar 05, 2009 - 2:30 a.m.

CVE-2009-0037

2009-03-0502:30:00
CWE-352
web.nvd.nist.gov
71
curl
libcurl
security
cve-2009-0037
http
remote attacks

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

81.1%

The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which might allow remote HTTP servers to (1) trigger arbitrary requests to intranet servers, (2) read or overwrite arbitrary files via a redirect to a file: URL, or (3) execute arbitrary commands via a redirect to an scp: URL.

Affected configurations

NVD
Node
curlcurlMatch5.11
OR
curlcurlMatch6.0
OR
curlcurlMatch6.1beta
OR
curlcurlMatch6.2
OR
curlcurlMatch6.3
OR
curlcurlMatch6.3.1
OR
curlcurlMatch6.4
OR
curlcurlMatch6.5
OR
curlcurlMatch6.5.1
OR
curlcurlMatch6.5.2
OR
curlcurlMatch7.1
OR
curlcurlMatch7.1.1
OR
curlcurlMatch7.2
OR
curlcurlMatch7.2.1
OR
curlcurlMatch7.3
OR
curlcurlMatch7.4
OR
curlcurlMatch7.4.1
OR
curlcurlMatch7.4.2
OR
curlcurlMatch7.5
OR
curlcurlMatch7.5.1
OR
curlcurlMatch7.5.2
OR
curlcurlMatch7.6
OR
curlcurlMatch7.6.1
OR
curlcurlMatch7.7
OR
curlcurlMatch7.7.1
OR
curlcurlMatch7.7.2
OR
curlcurlMatch7.7.3
OR
curlcurlMatch7.8
OR
curlcurlMatch7.8.1
OR
curlcurlMatch7.8.2
OR
curlcurlMatch7.9
OR
curlcurlMatch7.9.1
OR
curlcurlMatch7.9.2
OR
curlcurlMatch7.9.3
OR
curlcurlMatch7.9.4
OR
curlcurlMatch7.9.5
OR
curlcurlMatch7.9.6
OR
curlcurlMatch7.9.7
OR
curlcurlMatch7.9.8
OR
curlcurlMatch7.10
OR
curlcurlMatch7.10.1
OR
curlcurlMatch7.10.2
OR
curlcurlMatch7.10.3
OR
curlcurlMatch7.10.4
OR
curlcurlMatch7.10.5
OR
curlcurlMatch7.10.6
OR
curlcurlMatch7.10.7
OR
curlcurlMatch7.10.8
OR
curlcurlMatch7.11.1
OR
curlcurlMatch7.12
OR
curlcurlMatch7.12.1
OR
curlcurlMatch7.12.2
OR
curlcurlMatch7.13
OR
curlcurlMatch7.13.2
OR
curlcurlMatch7.14
OR
curlcurlMatch7.14.1
OR
curlcurlMatch7.15
OR
curlcurlMatch7.15.1
OR
curlcurlMatch7.15.3
OR
curlcurlMatch7.16.3
OR
curlcurlMatch7.16.4
OR
curlcurlMatch7.17
OR
curlcurlMatch7.18
OR
curlcurlMatch7.19.3
OR
curllibcurlMatch5.11
OR
curllibcurlMatch7.12
OR
curllibcurlMatch7.12.1
OR
curllibcurlMatch7.12.2
OR
curllibcurlMatch7.12.3
OR
curllibcurlMatch7.13
OR
curllibcurlMatch7.13.1
OR
curllibcurlMatch7.13.2
OR
curllibcurlMatch7.14
OR
curllibcurlMatch7.14.1
OR
curllibcurlMatch7.15
OR
curllibcurlMatch7.15.1
OR
curllibcurlMatch7.15.2
OR
curllibcurlMatch7.15.3
OR
curllibcurlMatch7.16.3
OR
curllibcurlMatch7.19.3

References

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

81.1%