Update of /cvsroot/curl/curl-www/docs
In directory labb:/tmp/cvs-serv17377
Modified Files:
_security.html
Log Message:
modified layout, added 'permalinks' all over, added BID to the recent flaw
Index: _security.html
===================================================================
RCS file: /cvsroot/curl/curl-www/docs/_security.html,v
retrieving revision 1.10
retrieving revision 1.11
diff -u -d -r1.10 -r1.11
--- _security.html 13 Oct 2005 21:38:02 -0000 1.10
+++ _security.html 14 Oct 2005 06:42:14 -0000 1.11
@@ -35,16 +35,20 @@
We appreciate getting notified in advance before you go public with security
advisories for the sake of our users.
+<a name="BID15102"></a><a name="CAN-2005-3185"></a>
SUBTITLE(libcurl NTLM Buffer Overflow)
<p>
- October 13, 2005<br>
- Mitre: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3185">CAN-2005-3185</a><br>
- Affected versions: curl and libcurl 7.10.6 to and including 7.14.1<br>
- Not affected versions: curl and libcurl 7.10.5 and earlier, 7.15.0 and later<br>
- Patch: <a href="http://curl.haxx.se/libcurl-ntlmbuf.patch">libcurl-ntlmbuf.patch</a><br>
- Advisory: <a href="adv_20051013.html">Project cURL Security Advisory</a>, <a
+<table class="news">
+ <tr><td>Date:</td><td>October 13, 2005</td></tr>
+ <tr><td>ID</td><td><a href="http://www.securityfocus.com/bid/15102">BID 15102</a> <a
+ href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-3185">CAN-2005-3185</a> <small><a href="#BID15102">(permalink)</a></small></td></tr>
+ <tr><td>Affected versions</td><td>curl and libcurl 7.10.6 to and including 7.14.1</td></tr>
+ <tr><td>Not affected versions</td><td>curl and libcurl 7.10.5 and earlier, 7.15.0 and later</td></tr>
+ <tr><td>Patch</td><td><a href="http://curl.haxx.se/libcurl-ntlmbuf.patch">libcurl-ntlmbuf.patch</a></td></tr>
+ <tr><td>Advisories</td><td><a href="adv_20051013.html">Project cURL Security Advisory</a>, <a
href="http://www.idefense.com/application/poi/display?id=322&type=vulnerabilities">iDEFENSE's
- advisory</a>
+ advisory</a></td></tr>
+</table>
<p>
libcurl's NTLM function can overflow a stack-based buffer if given a too long
user name or domain name. This would happen if you enable NTLM authentication
@@ -63,14 +67,15 @@
The <a
href="http://article.gmane.org/gmane.comp.web.wget.general/5064">notification
mail</a> to us about this flaw was also sent to a public wget mailing list
- and thus became official immediately.
+ and thus became public immediately.
-<a name="BID12616"></a>
+<a name="BID12616"></a><a name="CAN-2005-0490"></a>
SUBTITLE(Kerberos Authentication Buffer Overflow)
<p>
- February 21, 2005 <a href="http://www.securityfocus.com/bid/12616">BID
+ Date: February 21, 2005<br>
+ ID: <a href="http://www.securityfocus.com/bid/12616">BID
12616</a> <a
- href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0490">CAN-2005-0490</a> <br>
+ href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0490">CAN-2005-0490</a> <small><a href="#BID12616">(permalink)</a></small> <br>
Affected versions: 7.3 to and including 7.13.0<br>
Not affected versions: 7.13.1 and later
<p>
@@ -85,9 +90,10 @@
<a name="BID12615"></a>
SUBTITLE(NTLM Authentication Buffer Overflow)
<p>
- February 21, 2005 <a href="http://www.securityfocus.com/bid/12615">BID
+ Date: February 21, 2005<br>
+ ID: <a href="http://www.securityfocus.com/bid/12615">BID
12615</a> <a
- href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0490">CAN-2005-0490</a><br>
+ href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0490">CAN-2005-0490</a> <small><a href="#BID12615">(permalink)</a></small><br>
Affected versions: 7.10.6 to and including 7.13.0<br>
Not affected versions: 7.13.1 and later
<p>
@@ -100,7 +106,8 @@
<a name="BID8432"></a>
SUBTITLE(Proxy Authentication Header Information Leakage)
<p>
- August 3, 2003 <a href="http://www.securityfocus.com/bid/8432">BID 8432</a><br>
+ Date: August 3, 2003<br>
+ ID: <a href="http://www.securityfocus.com/bid/8432">BID 8432</a> <small><a href="#BID8432">(permalink)</a></small><br>
Affected versions: 7.1 to and including 7.10.6<br>
Not affected versions: 7.10.7 and later
<p>
@@ -111,9 +118,10 @@
<a name="BID1804"></a>
SUBTITLE(FTP Server Response Buffer Overflow)
<o>
- October 13, 2000 <a href="http://www.securityfocus.com/bid/1804">BID
+ Date: October 13, 2000<br>
+ ID: <a href="http://www.securityfocus.com/bid/1804">BID
1804</a> <a
- href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0973">CVE-2000-0973</a> <br>
+ href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0973">CVE-2000-0973</a> <small><a href="#BID1804">(permalink)</a></small><br>
Affected versions: 6.0 (and possibly earlier) to and including 7.4<br>
Not affected versions: 7.4.1 and later
<p>
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.