• CVE-2023-27534

发布时间: 2023年3月31日

修改时间: 2024年10月31日

概要

A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path relative to the user's home directory. Attackers can exploit this flaw to bypass filtering or execute arbitrary code by crafting a path like /~2/foo while accessing a server with a specific user.

CVSS v3 指标

NVD openEuler
Confidentiality High Low
Attack Vector Network Local
CVSS评分 8.8 4.5
Attack Complexity Low High
Privileges Required Low Low
Scope Unchanged Unchanged
Integrity High Low
User Interaction None None
Availability High Low

安全公告

公告名 概要 发布时间
KylinSec-SA-2023-1240 curl security update 2023年3月31日
KylinSec-SA-2023-1253 curl security update 2023年3月31日
KylinSec-SA-2023-1887 curl security update 2023年3月31日
KylinSec-SA-2023-2126 curl security update 2023年3月31日

影响产品

产品 状态
KY3.4-4A curl Fixed
KY3.4-5A curl Fixed
KY3.5.1 curl Fixed
KY3.5.2 curl Fixed