FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2010-0734

This CVE name corresponds to:

Entered Topic
2010-04-19 curl -- libcurl buffer overflow vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2010-0734
Phase Assigned(20100226)

Description

content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that requests automatic decompression, which might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact by sending crafted compressed data to an application that relies on the intended data-length limit.

References

Source Reference
BUGTRAQ 20101027 rPSA-2010-0072-1 curl
BUGTRAQ 20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX
MLIST [oss-security] 20100209 CVE Request -- cURL/libCURL 7.20.0
MLIST [oss-security] 20100309 Re: CVE Request -- cURL/libCURL 7.20.0
MLIST [oss-security] 20100316 Re: CVE Request -- cURL/libCURL 7.20.0
CONFIRM http://curl.haxx.se/docs/adv_20100209.html
CONFIRM http://curl.haxx.se/docs/security.html#20100209
CONFIRM http://curl.haxx.se/libcurl-contentencoding.patch
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=563220
CONFIRM http://support.avaya.com/css/P8/documents/100081819
CONFIRM http://support.apple.com/kb/HT4188
CONFIRM http://wiki.rpath.com/Advisories:rPSA-2010-0072
CONFIRM http://www.vmware.com/security/advisories/VMSA-2011-0003.html
APPLE APPLE-SA-2010-06-15-1
DEBIAN DSA-2023
FEDORA FEDORA-2010-2720
FEDORA FEDORA-2010-2762
MANDRIVA MDVSA-2010:062
REDHAT RHSA-2010:0329
UBUNTU USN-1158-1
OVAL oval:org.mitre.oval:def:10760
OVAL oval:org.mitre.oval:def:6756
SECUNIA 38843
SECUNIA 38981
SECUNIA 39087
SECUNIA 39734
SECUNIA 40220
SECUNIA 45047
VUPEN ADV-2010-0571
VUPEN ADV-2010-0602
VUPEN ADV-2010-0660
VUPEN ADV-2010-0725
VUPEN ADV-2010-1481