Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-8817

Опубликовано: 29 нояб. 2017
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a string that ends with an '[' character.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
.NET Core 1.0 on Red Hat Enterprise Linuxrh-dotnetcore10-curlOut of support scope
.NET Core 1.1 on Red Hat Enterprise Linuxrh-dotnetcore11-curlOut of support scope
.NET Core 2.0 on Red Hat Enterprise Linuxrh-dotnet20-curlOut of support scope
.NET Core 2.1 on Red Hat Enterprise Linuxrh-dotnet21-curlWill not fix
Red Hat Enterprise Linux 5curlNot affected
Red Hat Enterprise Linux 6curlNot affected
Red Hat Enterprise Linux 7curlWill not fix
Red Hat Enterprise Linux 8curlNot affected
Red Hat Software Collections for Red Hat Enterprise Linux 6httpd24-curlFixedRHSA-2018:355813.11.2018
Red Hat Software Collections for Red Hat Enterprise Linux 6httpd24-httpdFixedRHSA-2018:355813.11.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1515760curl: FTP wildcard out of bounds read

EPSS

Процентиль: 69%
0.0061
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 8 лет назад

The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a string that ends with an '[' character.

CVSS3: 9.8
nvd
около 8 лет назад

The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a string that ends with an '[' character.

CVSS3: 9.8
debian
около 8 лет назад

The FTP wildcard function in curl and libcurl before 7.57.0 allows rem ...

CVSS3: 9.8
github
больше 3 лет назад

The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a string that ends with an '[' character.

suse-cvrf
около 8 лет назад

Security update for curl

EPSS

Процентиль: 69%
0.0061
Низкий

3.1 Low

CVSS3