Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13442
HistoryMar 12, 2019 - 5:15 a.m.

Remote Code Execution (RCE)

2019-03-1205:15:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

EPSS

0.192

Percentile

96.3%

libcurl.so is vulnerable to remote code execution (RCE). An improper bounds check in the function that creates an outgoing NTLM type-3 header (lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()) results in a stack-based buffer overflow when a very large nt response data is extracted from a previous NTLMv2 header, allowing a remote attacker to exploit the vulnerability to execute arbitrary code, or crash the application.