Описание
When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the CURLOPT_ACCEPT_ENCODING
option, using zlib 1.2.0.3 or older, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | only with old zlib |
esm-infra-legacy/trusty | not-affected | only with old zlib |
esm-infra/bionic | not-affected | only with old zlib |
esm-infra/focal | not-affected | only with old zlib |
esm-infra/xenial | not-affected | only with old zlib |
focal | not-affected | only with old zlib |
jammy | not-affected | only with old zlib |
noble | not-affected | only with old zlib |
oracular | not-affected | only with old zlib |
upstream | needs-triage |
Показывать по
EPSS
7.3 High
CVSS3
Связанные уязвимости
When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.
When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.
When libcurl is asked to perform automatic gzip decompression of conte ...
When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.
EPSS
7.3 High
CVSS3