VDB
CVE-2005-3185
CVE-2005-3185
PUBLISHED
CVSS 7.5 HIGH
Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other products that use libcurl, when NTLM authentication is enabled, allows remote servers to execute arbitrary code via a long NTLM username.
EPSS 5.19% · 91.7th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
5.19%
91.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| curl | curl | 7.13.2 |
| wget | wget | 1.10 |
| libcurl | libcurl | 7.13.2 |
| n/a | n/a | n/a |
Timeline
- Oct 13, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- ADV-2005-2659 vdb
- TSLSA-2005-0059 vendor-advisory
- DSA-919 vendor-advisory
- ADV-2005-2088 vdb
- FEDORA-2005-1129 vendor-advisory
- SUSE-SA:2005:063 vendor-advisory
- APPLE-SA-2005-11-29 vendor-advisory
- 15102 vdb
- 17965 third-party-advisory
- ADV-2005-2125 vdb
- 15647 vdb
- GLSA-200510-19 vendor-advisory
- 19193 third-party-advisory
- 17485 third-party-advisory
- 82 third-party-advisory
- http://secunia.com/advisories/17192 advisory
- http://secunia.com/advisories/17203 advisory
- http://secunia.com/advisories/17208 advisory
- http://secunia.com/advisories/17403 advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:182 technical
…and 21 more