Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

FTP:CURL-OF-BANNER

Severity

High

Recommended

No

Recommended Action

Drop

Category

FTP

Keywords

cURL Malicious Server Buffer Overflow

Release Date

2003/04/22

Update Number

1213

Supported Platforms

di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

FTP: cURL Malicious Server Buffer Overflow


This signature detects attempts to exploit a known vulnerability against the cURL file retrieval client. cURL 6.1 to 7.4 versions are vulnerable. Attackers can use a malicious server to connect to the cURL client and execute arbitrary code with the permissions of the cURL user.

Extended Description

Curl is an open-source utility for sending or receiving files using URL syntax. A vulnerability exists in the version of curl included with Debian GNU/Linux 2.2 and FreeBSD (prior to 4.2 release). Note that cURL runs on other platforms as well, and earlier versions may be also vulnerable. Curl's error-logging feature improperly tests the size of generated error messages, which are sent from a remote host. A malicious remote server could send a maliciously-formed response to a request from curl, designed to exceed the maximum length of the error buffer. The contents of this oversized buffer, when copied onto the stack, can potentially overwrite the calling functions' return address. This can alter the program's flow of execution and result in arbitrary code being run on the client host.

Affected Products

  • Daniel Stenberg curl 6.0.0
  • Daniel Stenberg curl 6.1.0
  • Daniel Stenberg curl 6.1.0 Beta
  • Daniel Stenberg curl 6.3.0
  • Daniel Stenberg curl 6.4.0
  • Daniel Stenberg curl 6.5.0
  • Daniel Stenberg curl 6.5.1
  • Daniel Stenberg curl 6.5.2
  • Daniel Stenberg curl 7.1.0
  • Daniel Stenberg curl 7.1.1
  • Daniel Stenberg curl 7.2.0
  • Daniel Stenberg curl 7.2.1
  • Daniel Stenberg curl 7.3.0
  • Daniel Stenberg curl 7.4.0

References

  • BugTraq: 1804
  • CVE: CVE-2000-0973
  • URL: http://curl.haxx.se/

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out