Attack (Attack ID:320445)

Release Date2015/09/01

Attack NameWEB-CLIENT cURL and libcurl Cookie Path Parsing Remote Code Execution -1 (CVE-2015-3145)

Severity

BUG ID

CVE ID

 

Description

A heap buffer underflow vulnerability exists in cURL and libcurl. The vulnerability is due error when parsing a cookie path in an HTTP response.
Impact:Remote code execution
Affected System:Windows
Additional References:CVE-2015-3145

 

Solution

Update vendor's patch.