Описание
When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the CURLOPT_ACCEPT_ENCODING option, using zlib 1.2.0.3 or older, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | only with old zlib |
| esm-infra-legacy/trusty | not-affected | only with old zlib |
| esm-infra/bionic | not-affected | only with old zlib |
| esm-infra/focal | not-affected | only with old zlib |
| esm-infra/xenial | not-affected | only with old zlib |
| focal | not-affected | only with old zlib |
| jammy | not-affected | only with old zlib |
| noble | not-affected | only with old zlib |
| oracular | not-affected | only with old zlib |
| upstream | needs-triage |
Показывать по
EPSS
7.3 High
CVSS3
Связанные уязвимости
When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.
When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.
When libcurl is asked to perform automatic gzip decompression of conte ...
When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.
EPSS
7.3 High
CVSS3