curl before version 7.52.0 is vulnerable to a buffer overflow when doing a large floating point output in libcurl's implementation of the printf() functions. If there are any application that accepts a format string from the outside without necessary input filtering, it could allow remote attacks.
2018-04-23T18:29:00.537
2024-11-21T03:01:26.577
Modified
CVSSv3.0: 5.9 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4