Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w3rm-phr3-x8q8

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."

The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."

EPSS

Процентиль: 77%
0.01008
Низкий

Дефекты

CWE-119

Связанные уязвимости

ubuntu
почти 11 лет назад

The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."

redhat
почти 11 лет назад

The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."

nvd
почти 11 лет назад

The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."

debian
почти 11 лет назад

The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 do ...

suse-cvrf
почти 11 лет назад

Security update for curl

EPSS

Процентиль: 77%
0.01008
Низкий

Дефекты

CWE-119