• nathris@lemmy.ca
    link
    fedilink
    arrow-up
    12
    ·
    2 years ago

    Could be an RCE exploit. Doesn’t matter if it’s privilege escalation at that point because it can be used to execute a payload that can.

    • taaz@biglemmowski.winOP
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      2 years ago

      To top it of it seems it’s also contained in libcurl, and getting RCEd just by doing a request does not sound fun.

    • PowerCrazy@lemmy.ml
      link
      fedilink
      arrow-up
      1
      arrow-down
      4
      ·
      2 years ago

      I’ll admit i’m out of my depth about exactly how curl works on the local system, but surely if there is a vulnerability in the “libcurl” library that is much more serious and severe then just saying “curl” is vulnerable.

      I’m assuming that libcurl touches a huge amount of the linux network stack.