A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of service or information leakage
2018-03-14T18:29:00.373
2024-11-21T03:39:43.603
Modified
CVSSv3.0: 9.1 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:N/A:P
10.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | debian | debian_linux | 7.0 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | canonical | ubuntu_linux | 12.04 | Yes |
Operating System | canonical | ubuntu_linux | 14.04 | Yes |
Operating System | canonical | ubuntu_linux | 16.04 | Yes |
Operating System | canonical | ubuntu_linux | 17.10 | Yes |
Application | haxx | curl | ≤ 7.58.0 | Yes |
Operating System | redhat | enterprise_linux_desktop | 7.0 | Yes |
Operating System | redhat | enterprise_linux_server | 7.0 | Yes |
Operating System | redhat | enterprise_linux_workstation | 7.0 | Yes |
Application | oracle | communications_webrtc_session_controller | < 7.2 | Yes |
Application | oracle | enterprise_manager_ops_center | 12.2.2 | Yes |
Application | oracle | enterprise_manager_ops_center | 12.3.3 | Yes |
Application | oracle | peoplesoft_enterprise_peopletools | 8.55 | Yes |
Application | oracle | peoplesoft_enterprise_peopletools | 8.56 | Yes |
Application | oracle | peoplesoft_enterprise_peopletools | 8.57 | Yes |