Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email email@example.com
From: David Kierznowski (david.kierznowskigmail.com)
Date: Tue Mar 03 2009 - 02:25:14 CST
cURL/libcURL Arbitrary File Access
Release date: 03/Jan/2009
Quote from: http://curl.haxx.se/libcurl/:
"libcurl is a free and easy-to-use client-side URL transfer library,
supporting FTP, FTPS,
HTTP, HTTPS, SCP, SFTP, TFTP, TELNET, DICT, LDAP, LDAPS and FILE."
This vulnerability could permit remote arbitrary file access and command
execution under “less-likely” circumstances.
This is a joint advisory release with cURL. The latest version addresses
Full advisory available here:
Full-Disclosure - We believe in it.
Hosted and sponsored by Secunia - http://secunia.com/