LWN.net Logo

curl: arbitrary code execution

Package(s):curl CVE #(s):
Created:March 9, 2010 Updated:March 15, 2010
Description: From the Red Hat bugzilla:

A stack based buffer overflow flaw was found in the way libcurl used to uncompress zlib compressed data. If an application, using libcurl, was downloading compressed content over HTTP and asked libcurl to automatically uncompress data, it might lead to denial of service (application crash) or, potentially, to arbitrary code execution with the privileges of that application.

Alerts:
Fedora FEDORA-2010-2720 2010-02-24
Fedora FEDORA-2010-2762 2010-02-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds