CVE-2005-3185
curl - buffer overflow
EPSS 5.2%
描述
Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other products that use libcurl, when NTLM authentication is enabled, allows remote servers to execute arbitrary code via a long NTLM username.
如何修補 CVE-2005-3185
要修補 CVE-2005-3185,請將受影響套件升級到下列已修補版本。
- Debian/curl—升級至 7.15.0-1 或更新版本
- Debian/curl—升級至 7.9.5-1woody2 或更新版本
- Debian/wget—升級至 1.10.2-1 或更新版本
CVE-2005-3185 正在被利用嗎?
中等 — EPSS 為 5.2%,可持續追蹤但非最高優先。
受影響套件(3)
- from 0, < 7.15.0-1
- from 0, < 7.9.5-1woody2
- from 0, < 1.10.2-1