CVE-2005-3185
Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other products that use libcurl, when NTLM authentication is enabled, allows remote servers to execute arbitrary code…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.19%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other products that use libcurl, when NTLM authentication is enabled, allows remote servers to execute arbitrary code via a long NTLM username.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 5.19% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- curl/curl · libcurl/libcurl · wget/wget
- Source
- cve@mitre.org
References
- ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.10/SCOSA-2006.10.txt
- http://docs.info.apple.com/article.html?artnum=302847
- http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.html
- http://secunia.com/advisories/17192Vendor Advisory
- http://secunia.com/advisories/17193Vendor Advisory
- http://secunia.com/advisories/17203Vendor Advisory
- http://secunia.com/advisories/17208Vendor Advisory
- http://secunia.com/advisories/17228Vendor Advisory
- http://secunia.com/advisories/17247Vendor Advisory
- http://secunia.com/advisories/17297Vendor Advisory
- http://secunia.com/advisories/17320Vendor Advisory
- http://secunia.com/advisories/17400Vendor Advisory
- http://secunia.com/advisories/17403Vendor Advisory
- http://secunia.com/advisories/17485Vendor Advisory
- http://secunia.com/advisories/17813Vendor Advisory
- http://secunia.com/advisories/17965Vendor Advisory
- http://secunia.com/advisories/19193Vendor Advisory
- http://securityreason.com/securityalert/82
- http://securitytracker.com/id?1015056
- http://securitytracker.com/id?1015057
- http://slackware.com/security/viewer.php?l=slackware-security&y=2005&m=slackware-security.519010
- http://www.debian.org/security/2005/dsa-919
- http://www.gentoo.org/security/en/glsa/glsa-200510-19.xml
- http://www.idefense.com/application/poi/display?id=322&type=vulnerabilitiesPatch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:182
- http://www.novell.com/linux/security/advisories/2005_63_wget_curl.html
- http://www.osvdb.org/20011
- http://www.redhat.com/archives/fedora-announce-list/2005-December/msg00020.html
- http://www.redhat.com/archives/fedora-announce-list/2005-October/msg00055.html
- http://www.redhat.com/support/errata/RHSA-2005-807.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.