Описание
Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string ending in a "%" (percent) character.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 7.31.0-1ubuntu1 |
lucid | released | 7.19.7-1ubuntu1.3 |
precise | released | 7.22.0-3ubuntu4.2 |
quantal | released | 7.27.0-1ubuntu1.3 |
raring | released | 7.29.0-1ubuntu3.1 |
upstream | released | 7.31.0-1 |
Показывать по
EPSS
6.8 Medium
CVSS2
Связанные уязвимости
Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string ending in a "%" (percent) character.
Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string ending in a "%" (percent) character.
Heap-based buffer overflow in the curl_easy_unescape function in lib/e ...
Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string ending in a "%" (percent) character.
EPSS
6.8 Medium
CVSS2