| |
|
|
|
cURL Mailing List Monthly Index Single Mail
curl-users Mailing List Archives
[Security Adviosory] libcurl Arbitrary File Access
From: Daniel Stenberg <daniel_at_haxx.se>
Date: Tue, 3 Mar 2009 00:13:15 +0100 (CET)
libcurl Arbitrary File Access
Project cURL Security Advisory, March 3rd 2009
1. VULNERABILITY
When told to follow a "redirect" automatically, libcurl does not question
This is a problem, for example, when the application is running on a server
The problem can also be exploited for uploading, if the rogue server
libcurl compiled to support SCP can get tricked to get a file using embedded
Files on servers other than the one running libcurl are also accessible when
There is no known exploit at the time of this writing.
The Common Vulnerabilities and Exposures (CVE) project has assigned the name
2. AFFECTED VERSIONS
Affected versions: curl and libcurl 5.11(!) to and including 7.19.3
Also note that (lib)curl is used by many applications, and not always
3. THE SOLUTION
libcurl 7.19.4 introduces a new option called CURLOPT_REDIR_PROTOCOLS, which
4. RECOMMENDATIONS
We suggest you take one of the following actions immediately, in order of
A - Upgrade to curl and libcurl 7.19.4
B - Apply the suitable patch and rebuild
For current CVS HEAD:
For curl 7.19.0:
For curl 7.18.2:
For curl 7.18.1:
For curl 7.16.4:
For curl 7.15.1:
For curl 7.11.0:
C - Disable automatic redirection following in your application and do the
5. TIME LINE
We were notified by David Kierznowski on Feb 6th, 2009.
We discussed solutions and a first patch was written and tested on Feb 11th.
Vendor-sec was contacted on Feb 12, 2009.
We agreed on and coordinated the synchronous disclosure of this problem
curl 7.19.4 was released on March 3 2009, just before this flaw was publicly
6. CREDITS
Reported to us by David Kierznowski. Thanks a lot!
Daniel Fandrich researched the issue and helped with the fix.
Michal Marek brought the SCP side of this issue and did a bunch of the
Daniel Stenberg wrote the primary patch and this advisory.
-- / daniel.haxx.se ------------------------------------------------------------------- List admin: http://cool.haxx.se/cgi-bin/mailman/listinfo/curl-users FAQ: http://curl.haxx.se/docs/faq.html Etiquette: http://curl.haxx.se/mail/etiquette.htmlReceived on 2009-03-03 These mail archives are generated by hypermail. |
Page updated November 12, 2010.
web site info