Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-8816

Опубликовано: 29 нояб. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vectors involving long user and password fields.

РелизСтатусПримечание
artful

released

7.55.1-1ubuntu2.2
devel

released

7.57.0-1ubuntu1
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/xenial

released

7.47.0-1ubuntu2.5
precise/esm

not-affected

code not present
trusty

not-affected

code not present
trusty/esm

not-affected

code not present
upstream

needs-triage

xenial

released

7.47.0-1ubuntu2.5
zesty

released

7.52.1-4ubuntu1.4

Показывать по

EPSS

Процентиль: 68%
0.00595
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
почти 8 лет назад

The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vectors involving long user and password fields.

CVSS3: 9.8
nvd
почти 8 лет назад

The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vectors involving long user and password fields.

CVSS3: 9.8
debian
почти 8 лет назад

The NTLM authentication feature in curl and libcurl before 7.57.0 on 3 ...

CVSS3: 9.8
github
больше 3 лет назад

The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vectors involving long user and password fields.

suse-cvrf
почти 8 лет назад

Security update for curl

EPSS

Процентиль: 68%
0.00595
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3