Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25763
HistoryJun 25, 2020 - 5:16 a.m.

Arbitrary File Overwrite

2020-06-2505:16:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.001 Low

EPSS

Percentile

41.4%

libcurl.so is vulnerable to arbitrary file overwrite. A logic flaw occurs when the -J flag is used together with -i option and are used in the reversed order. A malicious server will be able to overwrite arbitrary local files where the curl was executed by responding with malicious HTTP headers.