Release date:
Updated on:
Affected Systems:
Daniel Stenberg curl 7.x
Unaffected system:
Daniel Stenberg curl 7.24.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51665
Cve id: CVE-2012-0036
CURL is a command line FILE transmission tool that supports FTP, FTPS, HTTP, HTTPS, GOPHER, TELNET, DICT, FILE, and LDAP.
The cURL/libcURL implementation has the input verification vulnerability, which allows attackers to inject arbitrary data into the libcURL application and perform some illegal operations, for example, the POP3 client is tempted to delete messages or send unexpected messages to the SMTP server. This issue affects IMAP, POP3, and SMTP.
<* Source: Dan Fandrich
Link: http://curl.haxx.se/docs/adv_20120124.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Daniel Stenberg
---------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://curl.haxx.se/