CVE-2005-3185
published 2005-10-13CVE-2005-3185: Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other products that use…
PriorityP339high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.19%
91.5th percentile
Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other products that use libcurl, when NTLM authentication is enabled, allows remote servers to execute arbitrary code via a long NTLM username.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | — | — |
| debian | curl | < curl 7.15.0-1 (bookworm) | curl 7.15.0-1 (bookworm) |
| debian | wget | < curl 7.15.0-1 (bookworm) | curl 7.15.0-1 (bookworm) |
| gnu | wget | >= 0 < 1.10.2-1 | 1.10.2-1 |
| gnu | wget | >= 0 < 1.10.2-1 | 1.10.2-1 |
| gnu | wget | >= 0 < 1.10.2-1 | 1.10.2-1 |
| gnu | wget | >= 0 < 1.10.2-1 | 1.10.2-1 |
| haxx | curl | >= 0 < 7.15.0-1 | 7.15.0-1 |
| haxx | curl | >= 0 < 7.15.0-1 | 7.15.0-1 |
| haxx | curl | >= 0 < 7.15.0-1 | 7.15.0-1 |
| haxx | curl | >= 0 < 7.15.0-1 | 7.15.0-1 |
| libcurl | libcurl | — | — |
| wget | wget | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Curl and wget vulnerabilities
vendor_ubuntu·2005-10-14
CVE-2005-3185 Curl and wget vulnerabilities
Title: Curl and wget vulnerabilities
Summary: Curl and wget vulnerabilities
A buffer overflow has been found in the NTLM authentication handler of
the Curl library and wget. By tricking an user or automatic system
that uses the Curl library, the curl application, or wget into
visiting a specially-crafted web site, a remote attacker could exploit
this to execute arbitrary code with the privileges of the calling
user.
The Ubuntu 4.10 and 5.04 versions of wget are not affected by this.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2005-10-12·CVSS 7.5
CVE-2005-3185 [HIGH] security flaw
security flaw
Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other products that use libcurl, when NTLM authentication is enabled, allows remote servers to execute arbitrary code via a long NTLM username.
Debian
CVE-2005-3185: curl - Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) w...
vendor_debian·2005·CVSS 7.5
CVE-2005-3185 [HIGH] CVE-2005-3185: curl - Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) w...
Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other products that use libcurl, when NTLM authentication is enabled, allows remote servers to execute arbitrary code via a long NTLM username.
Scope: local
bookworm: resolved (fixed in 7.15.0-1)
bullseye: resolved (fixed in 7.15.0-1)
forky: resolved (fixed in 7.15.0-1)
sid: resolved (fixed in 7.15.0-1)
trixie: resolved (fixed in 7.15.0-1)
GHSA
GHSA-pr2f-jh2p-p39m: Stack-based buffer overflow in the ntlm_output function in http-ntlm
ghsa_unreviewed·2022-05-03
CVE-2005-3185 [HIGH] CWE-119 GHSA-pr2f-jh2p-p39m: Stack-based buffer overflow in the ntlm_output function in http-ntlm
Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other products that use libcurl, when NTLM authentication is enabled, allows remote servers to execute arbitrary code via a long NTLM username.
OSV
CVE-2005-3185: Stack-based buffer overflow in the ntlm_output function in http-ntlm
osv·2005-10-13·CVSS 7.5
CVE-2005-3185 [HIGH] CVE-2005-3185: Stack-based buffer overflow in the ntlm_output function in http-ntlm
Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other products that use libcurl, when NTLM authentication is enabled, allows remote servers to execute arbitrary code via a long NTLM username.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-3185 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2005-3185 [HIGH] CVE-2005-3185 security flaw
CVE-2005-3185 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other products that use libcurl, when NTLM authentication is enabled, allows remote servers to execute arbitrary code via a long NTLM username.
Bugzilla
CVE-2005-3185 NTLM buffer overflow
bugzilla·2005-10-13·CVSS 7.5
CVE-2005-3185 [HIGH] CVE-2005-3185 NTLM buffer overflow
CVE-2005-3185 NTLM buffer overflow
The NTLM authentication code in wget was derived form the libcurl NTLM auth, so
wget is vulnerable to this issue.
This text was scavanged from the libcurl advisory:
libcurl's NTLM function can overflow a stack-based buffer if given a too long
user name or domain name. This would happen if you enable NTLM authentication
and either:
A - pass in a user name and domain name to libcurl that together are longer
than 192 bytes
B - allow (lib)curl to follow HTTP "redirects" (Location: and the appropriate
HTTP 30x response code) and the new URL contains a URL with a user name
and domain name that together are longer than 192 bytes
Discussion:
Created attachment 119931
Proposed patch from upstream
---
This issue also affects RHEL2.1 and RHEL3
---
RHSA-20
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.10/SCOSA-2006.10.txthttp://docs.info.apple.com/article.html?artnum=302847http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.htmlhttp://secunia.com/advisories/17192http://secunia.com/advisories/17193http://secunia.com/advisories/17203http://secunia.com/advisories/17208http://secunia.com/advisories/17228http://secunia.com/advisories/17247http://secunia.com/advisories/17297http://secunia.com/advisories/17320http://secunia.com/advisories/17400http://secunia.com/advisories/17403http://secunia.com/advisories/17485http://secunia.com/advisories/17813http://secunia.com/advisories/17965http://secunia.com/advisories/19193http://securityreason.com/securityalert/82http://securitytracker.com/id?1015056http://securitytracker.com/id?1015057http://slackware.com/security/viewer.php?l=slackware-security&y=2005&m=slackware-security.519010http://www.debian.org/security/2005/dsa-919http://www.gentoo.org/security/en/glsa/glsa-200510-19.xmlhttp://www.idefense.com/application/poi/display?id=322&type=vulnerabilitieshttp://www.mandriva.com/security/advisories?name=MDKSA-2005:182http://www.novell.com/linux/security/advisories/2005_63_wget_curl.htmlhttp://www.osvdb.org/20011http://www.redhat.com/archives/fedora-announce-list/2005-December/msg00020.htmlhttp://www.redhat.com/archives/fedora-announce-list/2005-October/msg00055.htmlhttp://www.redhat.com/support/errata/RHSA-2005-807.htmlhttp://www.redhat.com/support/errata/RHSA-2005-812.htmlhttp://www.securityfocus.com/bid/15102http://www.securityfocus.com/bid/15647http://www.vupen.com/english/advisories/2005/2088http://www.vupen.com/english/advisories/2005/2125http://www.vupen.com/english/advisories/2005/2659https://exchange.xforce.ibmcloud.com/vulnerabilities/22721https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9810https://usn.ubuntu.com/205-1/ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2006.10/SCOSA-2006.10.txthttp://docs.info.apple.com/article.html?artnum=302847http://lists.trustix.org/pipermail/tsl-announce/2005-October/000354.htmlhttp://secunia.com/advisories/17192http://secunia.com/advisories/17193http://secunia.com/advisories/17203http://secunia.com/advisories/17208http://secunia.com/advisories/17228http://secunia.com/advisories/17247http://secunia.com/advisories/17297http://secunia.com/advisories/17320http://secunia.com/advisories/17400http://secunia.com/advisories/17403http://secunia.com/advisories/17485http://secunia.com/advisories/17813http://secunia.com/advisories/17965http://secunia.com/advisories/19193http://securityreason.com/securityalert/82http://securitytracker.com/id?1015056http://securitytracker.com/id?1015057http://slackware.com/security/viewer.php?l=slackware-security&y=2005&m=slackware-security.519010http://www.debian.org/security/2005/dsa-919http://www.gentoo.org/security/en/glsa/glsa-200510-19.xmlhttp://www.idefense.com/application/poi/display?id=322&type=vulnerabilitieshttp://www.mandriva.com/security/advisories?name=MDKSA-2005:182http://www.novell.com/linux/security/advisories/2005_63_wget_curl.htmlhttp://www.osvdb.org/20011http://www.redhat.com/archives/fedora-announce-list/2005-December/msg00020.htmlhttp://www.redhat.com/archives/fedora-announce-list/2005-October/msg00055.htmlhttp://www.redhat.com/support/errata/RHSA-2005-807.htmlhttp://www.redhat.com/support/errata/RHSA-2005-812.htmlhttp://www.securityfocus.com/bid/15102http://www.securityfocus.com/bid/15647http://www.vupen.com/english/advisories/2005/2088http://www.vupen.com/english/advisories/2005/2125http://www.vupen.com/english/advisories/2005/2659https://exchange.xforce.ibmcloud.com/vulnerabilities/22721https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9810https://usn.ubuntu.com/205-1/
2005-10-13
Published