Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-8816

Опубликовано: 29 нояб. 2017
Источник: debian

Описание

The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vectors involving long user and password fields.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
curlfixed7.57.0-1package
curlnot-affectedwheezypackage

Примечания

  • https://curl.haxx.se/docs/adv_2017-11e7.html

  • https://curl.haxx.se/CVE-2017-8816.patch

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vectors involving long user and password fields.

CVSS3: 7.5
redhat
почти 8 лет назад

The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vectors involving long user and password fields.

CVSS3: 9.8
nvd
почти 8 лет назад

The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vectors involving long user and password fields.

CVSS3: 9.8
github
больше 3 лет назад

The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vectors involving long user and password fields.

suse-cvrf
почти 8 лет назад

Security update for curl