Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w3rm-phr3-x8q8

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."

The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."

EPSS

Процентиль: 95%
0.10951
Средний

Дефекты

CWE-119

Связанные уязвимости

ubuntu
больше 11 лет назад

The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."

redhat
больше 11 лет назад

The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."

nvd
больше 11 лет назад

The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."

debian
больше 11 лет назад

The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 do ...

suse-cvrf
больше 11 лет назад

Security update for curl

EPSS

Процентиль: 95%
0.10951
Средний

Дефекты

CWE-119