curl is vulnerable to arbitrary code execution. The vulnerability exists as an off-by-one bug in curl makes it possible to execute arbitrary code on a user’s machine if the user can be tricked into executing curl with a carefully crafted URL.
CPE | Name | Operator | Version |
---|---|---|---|
curl | eq | 7.12.1__5.rhel4 | |
curl | eq | 7.12.1__6.rhel4 | |
curl | eq | 7.12.1__5.rhel4 | |
curl | eq | 7.12.1__6.rhel4 |
curl.haxx.se/docs/adv_20051207.html
docs.info.apple.com/article.html?artnum=307562
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.16/SCOSA-2006.16.txt
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2006.16/SCOSA-2006.16.txt
lists.apple.com/archives/security-announce/2006/May/msg00003.html
lists.apple.com/archives/security-announce/2008/Mar/msg00001.html
qa.openoffice.org/issues/show_bug.cgi?id=59032
secunia.com/advisories/17907
secunia.com/advisories/17960
secunia.com/advisories/17961
secunia.com/advisories/17965
secunia.com/advisories/17977
secunia.com/advisories/18105
secunia.com/advisories/18188
secunia.com/advisories/18336
secunia.com/advisories/19261
secunia.com/advisories/19433
secunia.com/advisories/19457
secunia.com/advisories/20077
www.debian.org/security/2005/dsa-919
www.gentoo.org/security/en/glsa/glsa-200512-09.xml
www.gentoo.org/security/en/glsa/glsa-200603-25.xml
www.hardened-php.net/advisory_242005.109.html
www.mandriva.com/security/advisories?name=MDKSA-2005:224
www.redhat.com/archives/fedora-announce-list/2005-December/msg00020.html
www.redhat.com/support/errata/RHSA-2005-875.html
www.securityfocus.com/archive/1/418849/100/0/threaded
www.securityfocus.com/bid/15756
www.securityfocus.com/bid/17951
www.trustix.org/errata/2005/0072/
www.us-cert.gov/cas/techalerts/TA06-132A.html
www.vupen.com/english/advisories/2005/2791
www.vupen.com/english/advisories/2006/0960
www.vupen.com/english/advisories/2006/1779
www.vupen.com/english/advisories/2008/0924/references
access.redhat.com/errata/RHSA-2005:875
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10855
usn.ubuntu.com/228-1/