Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-0500

Опубликовано: 11 июл. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 7.5
CVSS3: 9.8

Описание

Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including curl 7.60.0 has a heap-based buffer overflow that might be exploitable by an attacker who can control the data that curl transmits over SMTP with certain settings (i.e., use of a nonstandard --limit-rate argument or CURLOPT_BUFFERSIZE value).

РелизСтатусПримечание
artful

released

7.55.1-1ubuntu2.6
bionic

released

7.58.0-2ubuntu3.2
devel

not-affected

7.61.0-1
esm-infra-legacy/trusty

not-affected

7.47.0-1ubuntu2.8
esm-infra/bionic

released

7.58.0-2ubuntu3.2
esm-infra/xenial

not-affected

7.47.0-1ubuntu2.8
precise/esm

not-affected

trusty

not-affected

7.47.0-1ubuntu2.8
trusty/esm

not-affected

7.47.0-1ubuntu2.8
upstream

needs-triage

Показывать по

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 7 лет назад

Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including curl 7.60.0 has a heap-based buffer overflow that might be exploitable by an attacker who can control the data that curl transmits over SMTP with certain settings (i.e., use of a nonstandard --limit-rate argument or CURLOPT_BUFFERSIZE value).

CVSS3: 9.8
nvd
больше 7 лет назад

Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including curl 7.60.0 has a heap-based buffer overflow that might be exploitable by an attacker who can control the data that curl transmits over SMTP with certain settings (i.e., use of a nonstandard --limit-rate argument or CURLOPT_BUFFERSIZE value).

CVSS3: 9.8
debian
больше 7 лет назад

Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including cur ...

suse-cvrf
больше 7 лет назад

Security update for curl

suse-cvrf
больше 7 лет назад

Security update for curl

7.5 High

CVSS2

9.8 Critical

CVSS3

Уязвимость CVE-2018-0500