Mandriva Linux Security Advisory 2009-069 – A security vulnerability has been identified and fixed in curl, which could allow remote HTTP servers to (1) trigger arbitrary requests to intranet servers, (2) read or overwrite arbitrary files via a redirect to a file: URL, or (3) execute arbitrary commands via a redirect to an scp: URL. The updated packages have been patched to prevent this.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/75500/MDVSA-2009-069.txt
Source: https://packetstormsecurity.com/files/75500/Mandriva-Linux-Security-Advisory-2009-069.html

