bagder: curl-www _newslog.html,1.83,1.84
| Newsgroups | gmane.comp.web.curl.www.cvs |
|---|---|
| Message-ID | <[email protected]> |
Update of /cvsroot/curl/curl-www In directory labb:/tmp/cvs-serv29891 Modified Files: _newslog.html Log Message: buffer overflow Index: _newslog.html =================================================================== RCS file: /cvsroot/curl/curl-www/_newslog.html,v retrieving revision 1.83 retrieving revision 1.84 diff -u -d -r1.83 -r1.84 --- _newslog.html 1 Feb 2005 08:02:04 -0000 1.83 +++ _newslog.html 22 Feb 2005 07:57:08 -0000 1.84 @@ -31,6 +31,23 @@ NCOLE #endif + NSUBJ(libcurl NTLM Buffer Overflow) + NDATE(22 February 2005) + NCOLS + + As was <a href="http://www.securityfocus.com/archive/1/391042">posted to + bugtraq</a>, all versions of curl that supports NTLM has this flaw. The <a + href="http://cool.haxx.se/cvs.cgi/curl/lib/http_ntlm.c.diff?r1=1.36&r2=1.37">fix</a>. It + requires a malicious server to send an unexpectedly long NTLM response + header to trigger. (No, we were not contacted nor notified about this + problem before they went public.) + +<p> + I'll be away for a week now but I'll put together a new release when I get + back. + + NCOLE + NSUBJ(curl and libcurl 7.13.0) NDATE(1 February 2005) NCOLS _______________________________________________ http://cool.haxx.se/mailman/listinfo/curl-www-commits