Input validation error in cURL - CVE-2019-15601
Published: January 16, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied URL. A remote attacker can pass URL to the SMB share using the "file://" URI handler and read arbitrary files from local resources.
Example: file://localhost//hostname/home/secret.txt
Note, this issue affects Windows installations only.
Affected software
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
MySQL Server
MySQL Workbench
OSS Support Tools
openEuler
curl
curl-debuginfo
curl-debugsource
curl-help
libcurl
libcurl-devel
How to mitigate CVE-2019-15601
curl - update to 7.69.1-1
curl-debuginfo - update to 7.69.1-1
curl-debugsource - update to 7.69.1-1
curl-help - update to 7.69.1-1
libcurl - update to 7.69.1-1
libcurl-devel - update to 7.69.1-1