Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-16840

Опубликовано: 31 окт. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related to closing an easy handle. When closing and cleaning up an 'easy' handle in the Curl_close() function, the library code first frees a struct (without nulling the pointer) and might then subsequently erroneously write to a struct field within that already freed struct.

РелизСтатусПримечание
bionic

not-affected

7.58.0-2ubuntu3.3
cosmic

released

7.61.0-1ubuntu2.2
devel

released

7.61.0-1ubuntu2.2
esm-infra-legacy/trusty

not-affected

esm-infra-legacy/xenial

not-affected

esm-infra/bionic

not-affected

7.58.0-2ubuntu3.3
esm-infra/xenial

not-affected

precise/esm

not-affected

trusty

not-affected

trusty/esm

not-affected

Показывать по

EPSS

Процентиль: 88%
0.03398
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 5
redhat
почти 8 лет назад

A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related to closing an easy handle. When closing and cleaning up an 'easy' handle in the `Curl_close()` function, the library code first frees a struct (without nulling the pointer) and might then subsequently erroneously write to a struct field within that already freed struct.

CVSS3: 9.8
nvd
почти 8 лет назад

A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related to closing an easy handle. When closing and cleaning up an 'easy' handle in the `Curl_close()` function, the library code first frees a struct (without nulling the pointer) and might then subsequently erroneously write to a struct field within that already freed struct.

CVSS3: 9.8
debian
почти 8 лет назад

A heap use-after-free flaw was found in curl versions from 7.59.0 thro ...

CVSS3: 9.8
github
больше 4 лет назад

A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related to closing an easy handle. When closing and cleaning up an 'easy' handle in the `Curl_close()` function, the library code first frees a struct (without nulling the pointer) and might then subsequently erroneously write to a struct field within that already freed struct.

suse-cvrf
почти 8 лет назад

Security update for curl

EPSS

Процентиль: 88%
0.03398
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3