CVE-2009-0037 : Detail

CVE-2009-0037

Cross-Site Request Forgery - CSRF
A01-Broken Access Control
1.61%V3
Network
2009-03-05
01h00 +00:00
2018-10-11
17h57 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which might allow remote HTTP servers to (1) trigger arbitrary requests to intranet servers, (2) read or overwrite arbitrary files via a redirect to a file: URL, or (3) execute arbitrary commands via a redirect to an scp: URL.

CVE Informations

Related Weaknesses

CWE-ID Weakness Name Source
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

Metrics

Metrics Score Severity CVSS Vector Source
V2 6.8 AV:N/AC:M/Au:N/C:P/I:P/A:P [email protected]

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Exploit information

Exploit Database EDB-ID : 32834

Publication date : 2009-03-02 23h00 +00:00
Author : David Kierznowski
EDB Verified : Yes

source: https://www.securityfocus.com/bid/33962/info cURL/libcURL is prone to a security-bypass vulnerability. Remote attackers can exploit this issue to bypass certain security restrictions and carry out various attacks. This issue affects cURL/libcURL 5.11 through 7.19.3. Other versions may also be vulnerable. The following example redirection request may be used to carry out this attack: Location: scp://name:passwd@host/a'``;date >/tmp/test``;'

Products Mentioned

Configuraton 0

Curl>>Curl >> Version 5.11

    Curl>>Curl >> Version 6.0

      Curl>>Curl >> Version 6.1beta

        Curl>>Curl >> Version 6.2

          Curl>>Curl >> Version 6.3

            Curl>>Curl >> Version 6.3.1

              Curl>>Curl >> Version 6.4

                Curl>>Curl >> Version 6.5

                  Curl>>Curl >> Version 6.5.1

                    Curl>>Curl >> Version 6.5.2

                      Curl>>Curl >> Version 7.1

                        Curl>>Curl >> Version 7.1.1

                          Curl>>Curl >> Version 7.2

                            Curl>>Curl >> Version 7.2.1

                              Curl>>Curl >> Version 7.3

                                Curl>>Curl >> Version 7.4

                                  Curl>>Curl >> Version 7.4.1

                                    Curl>>Curl >> Version 7.4.2

                                      Curl>>Curl >> Version 7.5

                                        Curl>>Curl >> Version 7.5.1

                                          Curl>>Curl >> Version 7.5.2

                                            Curl>>Curl >> Version 7.6

                                              Curl>>Curl >> Version 7.6.1

                                                Curl>>Curl >> Version 7.7

                                                  Curl>>Curl >> Version 7.7.1

                                                    Curl>>Curl >> Version 7.7.2

                                                      Curl>>Curl >> Version 7.7.3

                                                        Curl>>Curl >> Version 7.8

                                                          Curl>>Curl >> Version 7.8.1

                                                            Curl>>Curl >> Version 7.8.2

                                                              Curl>>Curl >> Version 7.9

                                                                Curl>>Curl >> Version 7.9.1

                                                                  Curl>>Curl >> Version 7.9.2

                                                                    Curl>>Curl >> Version 7.9.3

                                                                      Curl>>Curl >> Version 7.9.4

                                                                        Curl>>Curl >> Version 7.9.5

                                                                          Curl>>Curl >> Version 7.9.6

                                                                            Curl>>Curl >> Version 7.9.7

                                                                              Curl>>Curl >> Version 7.9.8

                                                                                Curl>>Curl >> Version 7.10

                                                                                  Curl>>Curl >> Version 7.10.1

                                                                                    Curl>>Curl >> Version 7.10.2

                                                                                      Curl>>Curl >> Version 7.10.3

                                                                                        Curl>>Curl >> Version 7.10.4

                                                                                          Curl>>Curl >> Version 7.10.5

                                                                                            Curl>>Curl >> Version 7.10.6

                                                                                              Curl>>Curl >> Version 7.10.7

                                                                                                Curl>>Curl >> Version 7.10.8

                                                                                                  Curl>>Curl >> Version 7.11.1

                                                                                                    Curl>>Curl >> Version 7.12

                                                                                                      Curl>>Curl >> Version 7.12.1

                                                                                                        Curl>>Curl >> Version 7.12.2

                                                                                                          Curl>>Curl >> Version 7.13

                                                                                                            Curl>>Curl >> Version 7.13.2

                                                                                                              Curl>>Curl >> Version 7.14

                                                                                                                Curl>>Curl >> Version 7.14.1

                                                                                                                  Curl>>Curl >> Version 7.15

                                                                                                                    Curl>>Curl >> Version 7.15.1

                                                                                                                      Curl>>Curl >> Version 7.15.3

                                                                                                                        Curl>>Curl >> Version 7.16.3

                                                                                                                          Curl>>Curl >> Version 7.16.4

                                                                                                                            Curl>>Curl >> Version 7.17

                                                                                                                              Curl>>Curl >> Version 7.18

                                                                                                                                Curl>>Curl >> Version 7.19.3

                                                                                                                                  Curl>>Libcurl >> Version 5.11

                                                                                                                                    Curl>>Libcurl >> Version 7.12

                                                                                                                                      Curl>>Libcurl >> Version 7.12.1

                                                                                                                                        Curl>>Libcurl >> Version 7.12.2

                                                                                                                                          Curl>>Libcurl >> Version 7.12.3

                                                                                                                                            Curl>>Libcurl >> Version 7.13

                                                                                                                                              Curl>>Libcurl >> Version 7.13.1

                                                                                                                                                Curl>>Libcurl >> Version 7.13.2

                                                                                                                                                  Curl>>Libcurl >> Version 7.14

                                                                                                                                                    Curl>>Libcurl >> Version 7.14.1

                                                                                                                                                      Curl>>Libcurl >> Version 7.15

                                                                                                                                                        Curl>>Libcurl >> Version 7.15.1

                                                                                                                                                          Curl>>Libcurl >> Version 7.15.2

                                                                                                                                                            Curl>>Libcurl >> Version 7.15.3

                                                                                                                                                              Curl>>Libcurl >> Version 7.16.3

                                                                                                                                                                Curl>>Libcurl >> Version 7.19.3

                                                                                                                                                                  References

                                                                                                                                                                  http://www.ubuntu.com/usn/USN-726-1
                                                                                                                                                                  Tags : vendor-advisory, x_refsource_UBUNTU
                                                                                                                                                                  http://secunia.com/advisories/34259
                                                                                                                                                                  Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                  http://curl.haxx.se/lxr/source/CHANGES
                                                                                                                                                                  Tags : x_refsource_CONFIRM
                                                                                                                                                                  http://secunia.com/advisories/35766
                                                                                                                                                                  Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                  http://secunia.com/advisories/34255
                                                                                                                                                                  Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                  http://www.redhat.com/support/errata/RHSA-2009-0341.html
                                                                                                                                                                  Tags : vendor-advisory, x_refsource_REDHAT
                                                                                                                                                                  http://www.debian.org/security/2009/dsa-1738
                                                                                                                                                                  Tags : vendor-advisory, x_refsource_DEBIAN
                                                                                                                                                                  http://www.vupen.com/english/advisories/2009/1865
                                                                                                                                                                  Tags : vdb-entry, x_refsource_VUPEN
                                                                                                                                                                  http://secunia.com/advisories/34138
                                                                                                                                                                  Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                  http://secunia.com/advisories/34202
                                                                                                                                                                  Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                  http://www.vupen.com/english/advisories/2009/0581
                                                                                                                                                                  Tags : vdb-entry, x_refsource_VUPEN
                                                                                                                                                                  http://www.securityfocus.com/bid/33962
                                                                                                                                                                  Tags : vdb-entry, x_refsource_BID
                                                                                                                                                                  http://support.apple.com/kb/HT4077
                                                                                                                                                                  Tags : x_refsource_CONFIRM
                                                                                                                                                                  http://security.gentoo.org/glsa/glsa-200903-21.xml
                                                                                                                                                                  Tags : vendor-advisory, x_refsource_GENTOO
                                                                                                                                                                  http://www.securitytracker.com/id?1021783
                                                                                                                                                                  Tags : vdb-entry, x_refsource_SECTRACK
                                                                                                                                                                  http://secunia.com/advisories/34251
                                                                                                                                                                  Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                  http://secunia.com/advisories/34399
                                                                                                                                                                  Tags : third-party-advisory, x_refsource_SECUNIA
                                                                                                                                                                  http://secunia.com/advisories/34237
                                                                                                                                                                  Tags : third-party-advisory, x_refsource_SECUNIA