RHEL 4 : curl (RHSA-2005:875)

Medium Nessus Plugin ID 20364


The remote Red Hat host is missing one or more security updates.


Updated curl packages that fix a security issue are now available for Red Hat Enterprise Linux 4.

This update has been rated as having moderate security impact by the Red Hat Security Response Team.

cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and Dict servers, using any of the supported protocols.

Stefan Esser discovered an off-by-one bug in curl. It may be possible to execute arbitrary code on a user's machine if the user can be tricked into executing curl with a carefully crafted URL. The Common Vulnerabilities and Exposures project assigned the name CVE-2005-4077 to this issue.

All users of curl are advised to upgrade to these updated packages, which contain a backported patch that resolves this issue.


Update the affected curl and / or curl-devel packages.

See Also



Plugin Details

Severity: Medium

ID: 20364

File Name: redhat-RHSA-2005-875.nasl

Version: $Revision: 1.16 $

Type: local

Agent: unix

Published: 2005/12/30

Modified: 2016/12/28

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:curl, p-cpe:/a:redhat:enterprise_linux:curl-devel, cpe:/o:redhat:enterprise_linux:4

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Patch Publication Date: 2005/12/20

Vulnerability Publication Date: 2005/12/07

Reference Information

CVE: CVE-2005-4077

OSVDB: 21509

RHSA: 2005:875