Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-8620

Опубликовано: 01 авг. 2018
Источник: debian
EPSS Низкий

Описание

The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read via user controlled input.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
curlfixed7.51.0-1package
curlnot-affectedwheezypackage

Примечания

  • https://github.com/curl/curl/commit/fbb5f1aa0326d485d5a7ac643b48481897ca667f

  • https://curl.haxx.se/docs/adv_20161102F.html

  • https://curl.haxx.se/CVE-2016-8620.patch

EPSS

Процентиль: 67%
0.00546
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 7 лет назад

The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read via user controlled input.

CVSS3: 6.5
redhat
больше 8 лет назад

The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read via user controlled input.

CVSS3: 6.5
nvd
почти 7 лет назад

The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read via user controlled input.

CVSS3: 9.8
github
около 3 лет назад

The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read via user controlled input.

suse-cvrf
больше 8 лет назад

Security update for curl

EPSS

Процентиль: 67%
0.00546
Низкий