Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-79v3-h2vf-vcg6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.

EPSS

Процентиль: 76%
0.01021
Низкий

7.8 High

CVSS3

Дефекты

CWE-427
CWE-94

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 6 лет назад

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.

CVSS3: 8.4
redhat
почти 6 лет назад

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.

CVSS3: 7.8
nvd
почти 6 лет назад

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.

CVSS3: 7.8
debian
почти 6 лет назад

A non-privileged user or program can put code and a config file in a k ...

CVSS3: 7.8
fstec
около 6 лет назад

Уязвимость библиотеки libcurl, связанная с неверным управлением генерацией кода, позволяющая нарушителю повысить свои привилегии или выполнить произвольный код

EPSS

Процентиль: 76%
0.01021
Низкий

7.8 High

CVSS3

Дефекты

CWE-427
CWE-94