[Full-disclosure] cURL/libcURL Arbitrary File Access
david.kierznowski at gmail.com
Tue Mar 3 08:25:14 GMT 2009
cURL/libcURL Arbitrary File Access
Release date: 03/Jan/2009
Quote from: http://curl.haxx.se/libcurl/:
"libcurl is a free and easy-to-use client-side URL transfer library,
supporting FTP, FTPS,
HTTP, HTTPS, SCP, SFTP, TFTP, TELNET, DICT, LDAP, LDAPS and FILE."
This vulnerability could permit remote arbitrary file access and command
execution under “less-likely” circumstances.
This is a joint advisory release with cURL. The latest version addresses
Full advisory available here:
-------------- next part --------------
An HTML attachment was scrubbed...
Full-Disclosure is hosted and sponsored by Secunia.