curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability appears to have been fixed in curl < 7.20.0 and curl >= 7.60.0.
2018-05-24T13:29:01.383
2024-11-21T03:39:58.987
Modified
CVSSv3.0: 9.1 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:N/A:P
10.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | debian | debian_linux | 7.0 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | canonical | ubuntu_linux | 12.04 | Yes |
Operating System | canonical | ubuntu_linux | 14.04 | Yes |
Operating System | canonical | ubuntu_linux | 16.04 | Yes |
Operating System | canonical | ubuntu_linux | 17.10 | Yes |
Operating System | canonical | ubuntu_linux | 18.04 | Yes |
Application | haxx | curl | ≤ 7.59.0 | Yes |
Operating System | redhat | enterprise_linux_desktop | 7.0 | Yes |
Operating System | redhat | enterprise_linux_server | 7.0 | Yes |
Operating System | redhat | enterprise_linux_workstation | 7.0 | Yes |
Application | oracle | communications_webrtc_session_controller | < 7.2 | Yes |
Application | oracle | enterprise_manager_ops_center | 12.2.2 | Yes |
Application | oracle | enterprise_manager_ops_center | 12.3.3 | Yes |
Application | oracle | peoplesoft_enterprise_peopletools | 8.55 | Yes |
Application | oracle | peoplesoft_enterprise_peopletools | 8.56 | Yes |
Application | oracle | peoplesoft_enterprise_peopletools | 8.57 | Yes |