CVE-2006-1061

Publication date 21 March 2006

Last updated 17 July 2025


Ubuntu priority

Heap-based buffer overflow in cURL and libcURL 7.15.0 through 7.15.2 allows remote attackers to execute arbitrary commands via a TFTP URL (tftp://) with a valid hostname and a long path.

Status

Package Ubuntu Release Status
curl 7.04 feisty
Fixed 7.15.5-1ubuntu2.1
6.10 edgy
Fixed 7.15.4-1ubuntu2.2
6.06 LTS dapper
Fixed 7.15.1-1ubuntu2.1