When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.
2025-02-05T10:15:22.980
2025-06-27T19:24:08.327
Analyzed
2499f714-1537-4658-8207-48ae4bb9eae9
CVSSv3.1: 7.3 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | netapp | hci_baseboard_management_controller | - | Yes |
Operating System | netapp | hci_h610s_firmware | - | Yes |
Hardware | netapp | hci_h610s | - | No |
Operating System | netapp | hci_h610c_firmware | - | Yes |
Hardware | netapp | hci_h610c | - | No |
Operating System | netapp | hci_h615c_firmware | - | Yes |
Hardware | netapp | hci_h615c | - | No |
Application | netapp | solidfire_\&_hci_management_node | - | Yes |
Application | netapp | solidfire_\&_hci_storage_node | - | Yes |
Application | haxx | curl | < 8.12.0 | Yes |
Application | haxx | libcurl | < 8.12.0 | Yes |
Application | zlib | zlib | ≤ 1.2.0.3 | No |