OpenBSD VuXML: Documenting security issues in the OpenBSD Ports & Packages Collection

curl -- authentication buffer overflow vulnerability

Affected packages
curl < 7.11.2p0

Details

VuXML ID 531c3456-94dc-11d9-a433-080020fe8945
Discovery 2004-12-21
Entry 2005-03-14

Two iDEFENSE Security Advisories reports:

An exploitable stack-based buffer overflow condition exists when using NT Lan Manager (NTLM) authentication. The problem specifically exists within Curl_input_ntlm() defined in lib/http_ntlm.c.

Successful exploitation allows remote attackers to execute arbitrary code under the privileges of the target user. Exploitation requires that an attacker either coerce or force a target to connect to a malicious server using NTLM authentication.

References

Bugtraq ID 12615
CVE Name CAN-2005-0490
Message FB24803D1DF2A34FA59FC157B77C970503E2462D@idserv04.idef.com