bagder: curl-www/docs _security.html,1.6,1.7
| Newsgroups | gmane.comp.web.curl.www.cvs |
|---|---|
| Message-ID | <[email protected]> |
Update of /cvsroot/curl/curl-www/docs In directory labb:/tmp/cvs-serv25892/docs Modified Files: _security.html Log Message: link to the advisory Index: _security.html =================================================================== RCS file: /cvsroot/curl/curl-www/docs/_security.html,v retrieving revision 1.6 retrieving revision 1.7 diff -u -d -r1.6 -r1.7 --- _security.html 13 Oct 2005 08:59:41 -0000 1.6 +++ _security.html 13 Oct 2005 09:02:19 -0000 1.7 @@ -40,7 +40,8 @@ October 13, 2005<br> Affected versions: curl and libcurl 7.10.6 to and including 7.14.1<br> Not affected versions: curl and libcurl 7.10.5 and earlier, 7.15.0 and later<br> - Patch: <a href="http://curl.haxx.se/libcurl-ntlmbuf.patch">libcurl-ntlmbuf.patch</a> + Patch: <a href="http://curl.haxx.se/libcurl-ntlmbuf.patch">libcurl-ntlmbuf.patch</a><br> + Advisory: <a href="http://curl.haxx.se/mail/lib-2005-10/0061.html">Project cURL Security Advisory</a> <p> libcurl's NTLM function can overflow a stack-based buffer if given a too long user name or domain name. This would happen if you enable NTLM authentication