CURL/libcurl Vulnerability (CVE-2015-3153)
CURL/libcurl Vulnerability (CVE-2015-3153)
Release date:
Updated on:
Affected Systems:
CURL <7.42.1
Description:
CVE (CAN) ID: CVE-2015-3153
CURL/libcURL is a command line FILE transmission tool that supports FTP, FTPS, HTTP, HTTPS, GOPHER, TELNET, DICT, FILE, and LDAP.
In versions earlier than cURL and libcurl 7.42.1, custom HTTP headers are sent to the proxy server and the target server in the default configuration. remote proxy servers can exploit this vulnerability to obtain sensitive information by reading the header content.
<* Source: Yehezkel Horowitz
Oren Souroujon
*>
Suggestion:
Vendor patch:
CURL
----
The vendor has released a patch to fix this security problem. Please download version 7.42.1 from the vendor's homepage:
Http://curl.haxx.se/CVE-2015-3153.patch
Or apply patches.
Or set CURLOPT_HEADEROPT to CURLHEADER_SEPARATE.
Ubuntu users install the download tool cURL 7.36.0
Linux curl
Sharing of Curl usage and common functions in Unix
Curl command
This article permanently updates the link address: