Описание
The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read via user controlled input.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
curl | fixed | 7.51.0-1 | package | |
curl | not-affected | wheezy | package |
Примечания
https://github.com/curl/curl/commit/fbb5f1aa0326d485d5a7ac643b48481897ca667f
https://curl.haxx.se/docs/adv_20161102F.html
https://curl.haxx.se/CVE-2016-8620.patch
EPSS
Связанные уязвимости
The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read via user controlled input.
The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read via user controlled input.
The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read via user controlled input.
The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read via user controlled input.
EPSS