发布时间: 2023年3月31日
修改时间: 2024年10月31日
A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.
NVD | openEuler | |
---|---|---|
Confidentiality | High | Low |
Attack Vector | Network | Local |
CVSS评分 | 8.8 | 4.5 |
Attack Complexity | Low | High |
Privileges Required | Low | Low |
Scope | Unchanged | Unchanged |
Integrity | High | Low |
User Interaction | None | None |
Availability | High | Low |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2023-1240 | curl security update | 2023年3月31日 |
KylinSec-SA-2023-1253 | curl security update | 2023年3月31日 |
KylinSec-SA-2023-1887 | curl security update | 2023年3月31日 |
KylinSec-SA-2023-2126 | curl security update | 2023年3月31日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-4A | curl | Fixed |
KY3.4-5A | curl | Fixed |
KY3.5.1 | curl | Fixed |
KY3.5.2 | curl | Fixed |