Heap-based buffer overflow in cURL and libcURL 7.15.0 through 7.15.2 allows remote attackers to execute arbitrary commands via a TFTP URL (tftp://) with a valid hostname and a long path.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Curl | Daniel_stenberg | 7.15.0 (including) | 7.15.0 (including) |
Curl | Daniel_stenberg | 7.15.1 (including) | 7.15.1 (including) |
Curl | Daniel_stenberg | 7.15.2 (including) | 7.15.2 (including) |
Curl | Ubuntu | dapper | * |
Curl | Ubuntu | devel | * |
Curl | Ubuntu | edgy | * |
Curl | Ubuntu | feisty | * |