CURL/libcURL 'fix _ hostname () 'Function Denial-of-Service Vulnerability (CVE-2015-3144)
CURL/libcURL 'fix _ hostname () 'Function Denial-of-Service Vulnerability (CVE-2015-3144)
Release date:
Updated on:
Affected Systems:
CURL 7.37.0-7.41.0
Description:
Bugtraq id: 74300
CVE (CAN) ID: CVE-2015-3144
CURL/libcURL is a command line FILE transmission tool that supports FTP, FTPS, HTTP, HTTPS, GOPHER, TELNET, DICT, FILE, and LDAP.
In cURL/libcURL 7.37.0-7.41.0, The fix_hostname function does not correctly calculate the index, which can cause remote denial of service.
<* Source: Hanno B & ouml; ck
*>
Suggestion:
Vendor patch:
CURL
----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://curl.haxx.se/docs/adv_20150422D.html
Ubuntu users install the download tool cURL 7.36.0
Linux curl
Sharing of Curl usage and common functions in Unix
Curl command
This article permanently updates the link address: