Debian Security Advisory

curl and curl-ssl -- remote exploit

Date Reported:
13 Oct 2000
Affected Packages:
curl, curl-ssl
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2000-0973.
More information:
The version of curl as distributed with Debian GNU/Linux 2.2 had a bug in the error logging code: When it created an error message it failed to check the size of the buffer allocated for storing the message. This could be exploited by the remote machine by returning an invalid response to a request from curl which overflows the error buffer and trick curl into executing arbitrary code.

Debian ships with two versions of curl: The normal curl package, and the crypto-enabled curl-ssl package. This bug has been fixed in curl version 6.0-1.1 and curl-ssl version 6.0-1.2 .

The first release of this advisory listed a wrongly compiled curl package for i386; this has been replaced with version 6.0-1.1.1 .

Fixed in:

Debian GNU/Linux 2.2 (potato)

curl-ssl

Source:
http://security.debian.org/dists/potato/updates/main/source/curl-ssl_6.0-1.2.diff.gz
http://security.debian.org/dists/potato/updates/main/source/curl-ssl_6.0-1.2.dsc
http://security.debian.org/dists/potato/updates/main/source/curl-ssl_6.0.orig.tar.gz
Alpha:
http://security.debian.org/dists/potato/updates/main/binary-alpha/curl-ssl_6.0-1.2_alpha.deb
ARM:
http://security.debian.org/dists/potato/updates/main/binary-arm/curl-ssl_6.0-1.2_arm.deb
Intel ia32:
http://security.debian.org/dists/potato/updates/main/binary-i386/curl-ssl_6.0-1.2_i386.deb
PowerPC:
http://security.debian.org/dists/potato/updates/main/binary-powerpc/curl-ssl_6.0-1.2_powerpc.deb
Sun Sparc:
http://security.debian.org/dists/potato/updates/main/binary-sparc/curl-ssl_6.0-1.2_sparc.deb

curl

Source:
http://security.debian.org/dists/potato/updates/main/source/curl_6.0-1.1.diff.gz
http://security.debian.org/dists/potato/updates/main/source/curl_6.0-1.1.dsc
http://security.debian.org/dists/potato/updates/main/source/curl_6.0.orig.tar.gz
Alpha:
http://security.debian.org/dists/potato/updates/main/binary-alpha/curl_6.0-1.1_alpha.deb
ARM:
http://security.debian.org/dists/potato/updates/main/binary-arm/curl_6.0-1.1_arm.deb
Intel ia32:
http://security.debian.org/dists/potato/updates/main/binary-i386/curl_6.0-1.1.1_i386.deb
PowerPC:
http://security.debian.org/dists/potato/updates/main/binary-powerpc/curl_6.0-1.1_powerpc.deb
Sun SPARC:
http://security.debian.org/dists/potato/updates/main/binary-sparc/curl_6.0-1.1_sparc.deb