Lucene search

K
freebsdFreeBSD9314058E-5204-11E7-B712-B1A44A034D72
HistoryJun 14, 2017 - 12:00 a.m.

cURL -- URL file scheme drive letter buffer overflow

2017-06-1400:00:00
vuxml.freebsd.org
10

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

0.002 Low

EPSS

Percentile

60.0%

cURL security advisory:

When libcurl is given either

  1. a file: URL that doesn’t use two slashes following the colon, or
  2. is told that file is the default scheme to use for URLs without scheme
    … and the given path starts with a drive letter and libcurl is built for
    Windows or DOS, then libcurl would copy the path with a wrong offset, so that
    the end of the given path would write beyond the malloc buffer. Up to seven
    bytes too much.
    We are not aware of any exploit of this flaw.
OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchcurl= 7.53.0UNKNOWN
FreeBSDanynoarchcurl< 7.54.1UNKNOWN

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

0.002 Low

EPSS

Percentile

60.0%