curl: improper input validation allows users to create a 'FILE:' URL that can make the client access a remote file using SMB
Published Jan 6, 2020
3.3
LOWCVSS 3.1
EPSS 0.24%
Description
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none
Affected products
No data.
No data.
No data.
.NET Core 2.1 on Red Hat Enterprise Linux
rh-dotnet21-curl
Not affected
.NET Core 2.2 on Red Hat Enterprise Linux
rh-dotnet22-curl
Not affected
Red Hat Enterprise Linux 5
curl
Not affected
Red Hat Enterprise Linux 6
curl
Not affected
Red Hat Enterprise Linux 7
curl
Not affected
Red Hat Enterprise Linux 8
curl
Not affected
Red Hat JBoss Core Services
jbcs-httpd24-curl
Not affected
Red Hat JBoss Web Server 5
curl
Not affected
Red Hat Software Collections
httpd24-curl
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| .NET Core 2.1 on Red Hat Enterprise Linux | rh-dotnet21-curl | Not affected | n/a |
| .NET Core 2.2 on Red Hat Enterprise Linux | rh-dotnet22-curl | Not affected | n/a |
| Red Hat Enterprise Linux 5 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 6 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 8 | curl | Not affected | n/a |
| Red Hat JBoss Core Services | jbcs-httpd24-curl | Not affected | n/a |
| Red Hat JBoss Web Server 5 | curl | Not affected | n/a |
| Red Hat Software Collections | httpd24-curl | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This bug only exists when libcurl runs on a Microsoft Windows operating system.
References (4)
- https://access.redhat.com/security/cve/CVE-2019-15601 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1794143 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2019-15601
- https://www.cve.org/CVERecord?id=CVE-2019-15601
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-15601 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1794143 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-15601 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-15601 |
Change history (0)
No recorded changes yet.