CVE-2005-0490
Multiple stack-based buffer overflows in libcURL and cURL 7.12.1, and possibly other versions, allow remote malicious web servers to execute arbitrary code via base64 encoded replies that exceed the intended buffer lengths when decoded, which is not…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple stack-based buffer overflows in libcURL and cURL 7.12.1, and possibly other versions, allow remote malicious web servers to execute arbitrary code via base64 encoded replies that exceed the intended buffer lengths when decoded, which is not properly handled by (1) the Curl_input_ntlm function in http_ntlm.c during NTLM authentication or (2) the Curl_krb_kauth and krb4_auth functions in krb4.c during Kerberos authentication.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 5.73% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-131
- Affected
- haxx/curl · haxx/libcurl
- Source
- cve@mitre.org
References
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000940Broken Link, Patch, Vendor Advisory
- http://marc.info/?l=full-disclosure&m=110959085507755&w=2Mailing List, Patch
- http://www.gentoo.org/security/en/glsa/glsa-200503-20.xmlThird Party Advisory
- http://www.idefense.com/application/poi/display?id=202&type=vulnerabilitiesBroken Link, Vendor Advisory
- http://www.idefense.com/application/poi/display?id=203&type=vulnerabilitiesBroken Link, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:048Third Party Advisory
- http://www.novell.com/linux/security/advisories/2005_11_curl.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2005-340.htmlBroken Link
- http://www.securityfocus.com/bid/12615Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/12616Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19423Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10273Broken Link
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000940Broken Link, Patch, Vendor Advisory
- http://marc.info/?l=full-disclosure&m=110959085507755&w=2Mailing List, Patch
- http://www.gentoo.org/security/en/glsa/glsa-200503-20.xmlThird Party Advisory
- http://www.idefense.com/application/poi/display?id=202&type=vulnerabilitiesBroken Link, Vendor Advisory
- http://www.idefense.com/application/poi/display?id=203&type=vulnerabilitiesBroken Link, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:048Third Party Advisory
- http://www.novell.com/linux/security/advisories/2005_11_curl.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2005-340.htmlBroken Link
- http://www.securityfocus.com/bid/12615Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/12616Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19423Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10273Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.