Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-3707

Опубликовано: 15 нояб. 2014
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3

Описание

The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to read sensitive memory information.

РелизСтатусПримечание
devel

released

7.38.0-3ubuntu1
esm-infra-legacy/trusty

released

7.35.0-1ubuntu2.2
lucid

released

7.19.7-1ubuntu1.10
precise

released

7.22.0-3ubuntu4.11
trusty

released

7.35.0-1ubuntu2.2
trusty/esm

released

7.35.0-1ubuntu2.2
upstream

released

7.39.0
utopic

released

7.37.1-1ubuntu3.1

Показывать по

4.3 Medium

CVSS2

Связанные уязвимости

redhat
около 11 лет назад

The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to read sensitive memory information.

nvd
почти 11 лет назад

The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to read sensitive memory information.

debian
почти 11 лет назад

The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, whe ...

github
больше 3 лет назад

The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to read sensitive memory information.

oracle-oval
почти 10 лет назад

ELSA-2015-2159: curl security, bug fix, and enhancement update (MODERATE)

4.3 Medium

CVSS2