Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 4th, 2009, 11:09 PM
axial axial is offline
Frequent Poster
 
Join Date: Jun 2007
Posts: 476
Default Security update for cURL

Quote:
A security update for cURL, the file transfer utility, and its associated libcurl library has been released to fix a vulnerability which could allow an attacker to examine files on a system, or possibly even write files. The cause of the problem is the cURL (Client for URL) automatic redirection feature.

This allows a remote site to redirect http:// requests to file:// which would then read a local file. A site that used cURL based applications could be tricked into downloading from what it thinks is a http:// URL and find itself redirected to using a local file, which may then be exposed in some other way by the site. According to the advisory the problem can also be exploited to overwrite local files. If SCP support has been enabled in libcurl, there is also a possibility that using embedded semi-colons can be used to execute commands on a server.

The H Security

Quote:
Also note that (lib)curl is used by many applications, and not always advertised as such.

http://curl.haxx.se/docs/adv_20090303.html
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:27 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums