A remote overflow exists in cURL/libCURL. cURL/libcURL fails to boundary check resulting in a heap overflow. With a specially crafted request, an attacker can cause arbitrary code execution by redirecting cURL/libcURL to a TFTP URL that exceeds 512 bytes in length resulting in a loss of integrity.
Classification
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
Solution
Upgrade to version 7.15.3 or higher, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround: reconfigure and compile cURL to remove TFTP support