| |
|
|
|
cURL Mailing List Monthly Index Single Mail
curl-users Mailing List Archives
libcurl NTLM Buffer Overflow Vulnerability
From: Daniel Stenberg <daniel-curl_at_haxx.se>
Date: Thu, 13 Oct 2005 10:50:27 +0200 (CEST)
libcurl NTLM Buffer Overflow Vulnerability
Project cURL Security Advisory, October 13th 2005
1. VULNERABILITY
libcurl's NTLM function can overflow a stack-based buffer if given a too long
A - pass in a user name and domain name to libcurl that together are longer
B - allow (lib)curl to follow HTTP "redirects" (Location: and the appropriate
There is no known exploit at the time of this writing.
2. AFFECTED VERSIONS
All versions of libcurl ever released with NTLM capabilities enabled are
libcurl builds with SSPI support (added in version 7.13.2 and only available
On non-Windows machines, the NTLM support requires the lib to have been built
Affected versions: curl and libcurl 7.10.6 to and including 7.14.1
Also note that (lib)curl is used by many applications, and not always
3. RECOMMENDATIONS
We *strongly* suggest you take one of the following actions immediately:
I - Upgrade to curl and libcurl 7.15.0
II - Apply the patch http://curl.haxx.se/libcurl-ntlmbuf.patch to your
III - Disable NTLM either by not enabling the command line option (to curl)
4. TIME LINE
We were notified by iDEFENSE at 22:15 local time October 12th 2005.
The notification mail was also sent to the wget camp (as they share pretty
The patch was produced within 30 minutes.
A number of distributors and packagers of curl were notified the same evening
Mailed vendor-sec 09:00 on October 13th
I noticed the "leak" of this flaw at 09:50 October 13th and mailed vendor-sec
5. CREDITS
Reported to us by iDEFENSE, original discoverer is anonymous
-- Commercial curl and libcurl Technical Support: http://haxx.se/curl.htmlReceived on 2005-10-13 These mail archives are generated by hypermail. |
Page updated November 12, 2010.
web site info