CVE-2005-0490
8.8 · HIGHOverview
CVE-2005-0490 is a high-severity vulnerability affecting haxx curl. It was published on May 2, 2005 and has a CVSS 3.1 base score of 8.8 (HIGH).
This vulnerability has a CVSS 3.1 base score of 8.8, rated HIGH. It can be exploited remotely over the network. Some level of privileges is required for exploitation.
Technical Description
Multiple stack-based buffer overflows in libcURL and cURL 7.12.1, and possibly other versions, allow remote malicious web servers to execute arbitrary code via base64 encoded replies that exceed the intended buffer lengths when decoded, which is not properly handled by (1) the Curl_input_ntlm function in http_ntlm.c during NTLM authentication or (2) the Curl_krb_kauth and krb4_auth functions in krb4.c during Kerberos authentication.
Remediation
Check the references section for vendor advisories and patches from haxx. Update curl to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
Affected Products
| Vendor | Product | Versions | Status |
|---|
References
Frequently Asked Questions
What is CVE-2005-0490?
CVE-2005-0490 is a high-severity vulnerability affecting haxx curl. It was published on May 2, 2005 and has a CVSS 3.1 base score of 8.8 (HIGH).
How severe is CVE-2005-0490?
This vulnerability has a CVSS 3.1 base score of 8.8, rated HIGH. It can be exploited remotely over the network. Some level of privileges is required for exploitation.
How do I fix or remediate CVE-2005-0490?
Check the references section for vendor advisories and patches from haxx. Update curl to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
How can CyberStrike help with CVE-2005-0490?
CyberStrike's AI-powered security agents can automatically detect CVE-2005-0490 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.
How CyberStrike Helps
AI agents map your attack surface to find vulnerabilities like this one.
Automated penetration testing that runs continuously, not just quarterly.
AI-driven PR review catches vulnerable dependencies before they ship.
Browser-based exploitation validates findings with real proof-of-concept.
Related HIGH CVEs from 2005
View all →Sudo 1.6.8p7 on SuSE Linux 9.3, and possibly other Linux distributions, allows local users to gain p
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users
FreeBSD 5.x to 5.4 on AMD64 does not properly initialize the IO permission bitmap used to allow user
SilverCity before 0.9.5-r1 installs (1) cgi-styler-form.py, (2) cgi-styler.py, and (3) source2html.p
Spectrum Cash Receipting System before 6.504 uses weak cryptography (static substitution) in the PAS
Integer underflow in pppd in cbcp.c for ppp 2.4.1 allows remote attackers to cause a denial of servi
Dnsmasq before 2.21 allows remote attackers to poison the DNS cache via answers to queries that were
Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of
D-Link DSL-504T stores usernames and passwords in cleartext in the router configuration file, which
The GIF parser in ateimg32.dll in AOL Instant Messenger (AIM) 5.9.3797 and earlier allows remote att
The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determ
VERITAS Backup Exec 9.0 through 10.0 for Windows Servers, and 9.0.4019 through 9.1.307 for Netware,