Description
curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the readworks, write a zero byte beyond its boundary.This will in most cases cause a segfault or similar, but circumstances might also cause different outcomes.If a malicious user can provide a custom netrc file to an application or otherwise affect its contents, this flaw could be used as denial-of-service.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-5702-1 | curl vulnerabilities |
References
History
Tue, 19 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Apple
Subscribe
Macos
Subscribe
Haxx
Subscribe
Curl
Subscribe
Netapp
Subscribe
Clustered Data Ontap
Subscribe
H300s
Subscribe
H300s Firmware
Subscribe
H410s
Subscribe
H410s Firmware
Subscribe
H500s
Subscribe
H500s Firmware
Subscribe
H700s
Subscribe
H700s Firmware
Subscribe
Splunk
Subscribe
Universal Forwarder
Subscribe
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-11-19T20:09:10.400Z
Reserved: 2022-07-06T00:00:00.000Z
Link: CVE-2022-35260
Updated: 2024-08-03T09:29:17.464Z
Status : Modified
Published: 2022-12-05T22:15:10.743
Modified: 2024-11-21T07:10:59.573
Link: CVE-2022-35260
OpenCVE Enrichment
No data.
Ubuntu USN