CURL-CVE-2010-3842

    Dashboard / Vulnerabilities / CURL-CVE-2010-3842

    CURL-CVE-2010-3842

    Published: 13 Oct 2010Last Modified: 27 May 2026
    Aliases:

    Summary: local file overwrite

    Details: curl offers a command line option --remote-header-name (also usable as -J) which uses the filename of the Content-disposition: header when it saves the downloaded data locally. curl attempts to cut off the directory parts from any given filename in the header to only store files in the current directory. It might overwrite a local file using the same name as the header specifies. The stripping of the directory did not take backslashes into account. On some operating systems, backslashes are used to separate directories and filenames. This allows a rogue server to send back a response that overwrites a filename in the local machine that the user is allowed to write, potentially a system file, a command or a known executable. Operating systems affected include Windows, Netware, MSDOS, OS/2 and Symbian. This error is only present in the curl command line tool, it is NOT a problem of the library libcurl.

    References:

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 7.20.0
    Fixed -7.21.2

    Affected versions

    7.21.1
    7.21.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High