curl 'Content-Disposition' HTTP Header Arbitrary File Overwrite Vulnerability
BID:44086
Info
curl 'Content-Disposition' HTTP Header Arbitrary File Overwrite Vulnerability
| Bugtraq ID: | 44086 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-3842 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 13 2010 12:00AM |
| Updated: | Oct 13 2010 12:00AM |
| Credit: | Dan Fandrich |
| Vulnerable: |
Daniel Stenberg curl 7.20 Daniel Stenberg curl 7.20.1 |
| Not Vulnerable: |
Daniel Stenberg curl 7.20.2 |
Discussion
curl 'Content-Disposition' HTTP Header Arbitrary File Overwrite Vulnerability
curl is prone to an arbitrary file-overwrite vulnerability because it fails to properly sanitize user-supplied data.
Attackers can overwrite arbitrary files on an unsuspecting user's computer in the context of the vulnerable application. Arbitrary code execution may also be possible.
curl 7.20.0 through 7.21.1 are vulnerable.
curl is prone to an arbitrary file-overwrite vulnerability because it fails to properly sanitize user-supplied data.
Attackers can overwrite arbitrary files on an unsuspecting user's computer in the context of the vulnerable application. Arbitrary code execution may also be possible.
curl 7.20.0 through 7.21.1 are vulnerable.
Exploit / POC
curl 'Content-Disposition' HTTP Header Arbitrary File Overwrite Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
curl 'Content-Disposition' HTTP Header Arbitrary File Overwrite Vulnerability
Solution:
Updates are available. Please see the references for details.
Daniel Stenberg curl 7.20.1
Daniel Stenberg curl 7.20
Solution:
Updates are available. Please see the references for details.
Daniel Stenberg curl 7.20.1
-
Daniel Stenberg curl-content-disposition.patch
http://curl.haxx.se/curl-content-disposition.patch
Daniel Stenberg curl 7.20
-
Daniel Stenberg curl-content-disposition.patch
http://curl.haxx.se/curl-content-disposition.patch
References
curl 'Content-Disposition' HTTP Header Arbitrary File Overwrite Vulnerability
References:
References:
- cURL homepage (Daniel Stenberg
) - CVE Request -- cURL / mingw32-cURL -- Did not strip directory parts separated by (Jan Lieskovsky)
- Security Advisory October 13 2010 (Daniel Stenberg)