Описание
An integer overflow in curl's URL API results in a buffer overflow in libcurl 7.62.0 to and including 7.64.1.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| .NET Core 1.0 on Red Hat Enterprise Linux | rh-dotnetcore10-curl | Not affected | ||
| .NET Core 1.1 on Red Hat Enterprise Linux | rh-dotnetcore11-curl | Not affected | ||
| .NET Core 2.1 on Red Hat Enterprise Linux | rh-dotnet21-curl | Not affected | ||
| .NET Core 2.2 on Red Hat Enterprise Linux | rh-dotnet22-curl | Not affected | ||
| Red Hat Enterprise Linux 5 | curl | Not affected | ||
| Red Hat Enterprise Linux 6 | curl | Not affected | ||
| Red Hat Enterprise Linux 7 | curl | Not affected | ||
| Red Hat Enterprise Linux 8 | curl | Not affected | ||
| Red Hat JBoss Web Server 5 | curl | Not affected | ||
| Red Hat Software Collections | httpd24-curl | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Low
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=1710609curl: Integer overflows in curl_url_set() function
EPSS
Процентиль: 39%
0.00177
Низкий
3.7 Low
CVSS3
Связанные уязвимости
CVSS3: 3.7
ubuntu
больше 6 лет назад
An integer overflow in curl's URL API results in a buffer overflow in libcurl 7.62.0 to and including 7.64.1.
CVSS3: 3.7
nvd
больше 6 лет назад
An integer overflow in curl's URL API results in a buffer overflow in libcurl 7.62.0 to and including 7.64.1.
CVSS3: 3.7
debian
больше 6 лет назад
An integer overflow in curl's URL API results in a buffer overflow in ...
CVSS3: 3.7
github
больше 3 лет назад
An integer overflow in curl's URL API results in a buffer overflow in libcurl 7.62.0 to and including 7.64.1.
CVSS3: 3.7
fstec
больше 6 лет назад
Уязвимость функции curl_url_set() библиотеки libcurl, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
Процентиль: 39%
0.00177
Низкий
3.7 Low
CVSS3