Lucene search

K
nessusTenable9760.PRM
HistoryNov 11, 2016 - 12:00 a.m.

cURL/libcurl 7.x < 7.47.0 Multiple Vulnerabilities

2016-11-1100:00:00
Tenable
www.tenable.com
17

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

7.3 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

0.017 Low

EPSS

Percentile

87.8%

Versions of cURL and libcurl prior to 7.47.0 are affected by multiple vulnerabilities :

  • A flaw exists that allows traversing outside of a restricted path. The issue is due to the program not properly sanitizing colon characters, specifically path traversal style attacks (e.g. ‘…/’) supplied via file names. With a specially crafted file name, a context-dependent attacker can write arbitrary files. (CVE-2016-0754)
  • A flaw exists in the ‘ConnectionExists()’ function in ‘lib/url.c’ that is triggered as credentials are not properly compared in proxy NTLM authentication. This may allow a remote attacker to reuse connections. (CVE-2016-0755)
Binary data 9760.prm
VendorProductVersionCPE
haxxcurlcpe:/a:haxx:curl

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

7.3 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

0.017 Low

EPSS

Percentile

87.8%