Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vvqh-cqpj-5537

Опубликовано: 05 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the CURLOPT_ACCEPT_ENCODING option, using zlib 1.2.0.3 or older, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.

When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the CURLOPT_ACCEPT_ENCODING option, using zlib 1.2.0.3 or older, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.

EPSS

Процентиль: 34%
0.00135
Низкий

7.3 High

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 7.3
ubuntu
5 месяцев назад

When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.

CVSS3: 4
redhat
5 месяцев назад

When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.

CVSS3: 7.3
nvd
5 месяцев назад

When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.

CVSS3: 7.3
msrc
4 месяца назад

Описание отсутствует

CVSS3: 7.3
debian
5 месяцев назад

When libcurl is asked to perform automatic gzip decompression of conte ...

EPSS

Процентиль: 34%
0.00135
Низкий

7.3 High

CVSS3

Дефекты

CWE-120