Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21512
HistorySep 13, 2019 - 6:08 a.m.

Arbitrary Code Execution

2019-09-1306:08:57
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18

0.012 Low

EPSS

Percentile

85.0%

libcurl.so is vulnerable to arbitrary code execution. A double-free occurs when a malicious server claims to send a large block that results in the realloc() function call to fail. The vulnerability exists when curl uses kerberos over FTP, and can be exploited by an attacker to execute arbitrary code on the system.

References