Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-7407

Опубликовано: 03 апр. 2017
Источник: ubuntu
Приоритет: negligible
EPSS Низкий
CVSS2: 2.1
CVSS3: 2.4

Описание

The ourWriteOut function in tool_writeout.c in curl 7.53.1 might allow physically proximate attackers to obtain sensitive information from process memory in opportunistic circumstances by reading a workstation screen during use of a --write-out argument ending in a '%' character, which leads to a heap-based buffer over-read.

РелизСтатусПримечание
artful

not-affected

7.55.1-1ubuntu1
devel

not-affected

7.55.1-1ubuntu1
esm-infra-legacy/trusty

released

7.35.0-1ubuntu2.11
esm-infra-legacy/xenial

released

7.47.0-1ubuntu2.3
esm-infra/xenial

released

7.47.0-1ubuntu2.3
precise

ignored

end of life
precise/esm

not-affected

7.22.0-3ubuntu4.18
trusty

released

7.35.0-1ubuntu2.11
trusty/esm

released

7.35.0-1ubuntu2.11
upstream

released

7.54.0,7.52.1-4

Показывать по

EPSS

Процентиль: 45%
0.00581
Низкий

2.1 Low

CVSS2

2.4 Low

CVSS3

Связанные уязвимости

CVSS3: 2.4
redhat
больше 9 лет назад

The ourWriteOut function in tool_writeout.c in curl 7.53.1 might allow physically proximate attackers to obtain sensitive information from process memory in opportunistic circumstances by reading a workstation screen during use of a --write-out argument ending in a '%' character, which leads to a heap-based buffer over-read.

CVSS3: 2.4
nvd
больше 9 лет назад

The ourWriteOut function in tool_writeout.c in curl 7.53.1 might allow physically proximate attackers to obtain sensitive information from process memory in opportunistic circumstances by reading a workstation screen during use of a --write-out argument ending in a '%' character, which leads to a heap-based buffer over-read.

CVSS3: 2.4
debian
больше 9 лет назад

The ourWriteOut function in tool_writeout.c in curl 7.53.1 might allow ...

CVSS3: 2.4
github
больше 4 лет назад

The ourWriteOut function in tool_writeout.c in curl 7.53.1 might allow physically proximate attackers to obtain sensitive information from process memory in opportunistic circumstances by reading a workstation screen during use of a --write-out argument ending in a '%' character, which leads to a heap-based buffer over-read.

suse-cvrf
больше 9 лет назад

Security update for curl

EPSS

Процентиль: 45%
0.00581
Низкий

2.1 Low

CVSS2

2.4 Low

CVSS3