5.8 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:N/I:P/A:P
0.003 Low
EPSS
Percentile
70.0%
Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote servers to create or overwrite arbitrary files by using \ (backslash) as a separator of path components within the Content-disposition HTTP header.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 12 | all | curl | < 7.88.1-10+deb12u6 | curl_7.88.1-10+deb12u6_all.deb |
Debian | 11 | all | curl | < 7.74.0-1.3+deb11u12 | curl_7.74.0-1.3+deb11u12_all.deb |
Debian | 999 | all | curl | < 8.8.0-2 | curl_8.8.0-2_all.deb |
Debian | 13 | all | curl | < 8.8.0-1 | curl_8.8.0-1_all.deb |