Количество 14
Количество 14

CVE-2019-3823
libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read contents will not be returned to the caller.

CVE-2019-3823
libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read contents will not be returned to the caller.

CVE-2019-3823
libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read contents will not be returned to the caller.
CVE-2019-3823
libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap ...
GHSA-xmjh-hmw3-hqhr
libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read contents will not be returned to the caller.

BDU:2019-01668
Уязвимость функции smtp_endofresp библиотеки libcurl, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

BDU:2019-00966
Уязвимость библиотеки libcurl, связанная с чтением за пределами границ буфера памяти, позволяющая нарушителю вызвать отказ в обслуживании

openSUSE-SU-2019:0174-1
Security update for curl

openSUSE-SU-2019:0173-1
Security update for curl

SUSE-SU-2019:0249-2
Security update for curl

SUSE-SU-2019:0249-1
Security update for curl

SUSE-SU-2019:0248-1
Security update for curl
ELSA-2019-3701
ELSA-2019-3701: curl security and bug fix update (MODERATE)

SUSE-SU-2019:0339-1
Security update for curl
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2019-3823 libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read contents will not be returned to the caller. | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад |
![]() | CVE-2019-3823 libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read contents will not be returned to the caller. | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад |
![]() | CVE-2019-3823 libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read contents will not be returned to the caller. | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад |
CVE-2019-3823 libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap ... | CVSS3: 4.3 | 1% Низкий | больше 6 лет назад | |
GHSA-xmjh-hmw3-hqhr libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read contents will not be returned to the caller. | CVSS3: 7.5 | 1% Низкий | около 3 лет назад | |
![]() | BDU:2019-01668 Уязвимость функции smtp_endofresp библиотеки libcurl, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации | CVSS3: 9.8 | 1% Низкий | больше 6 лет назад |
![]() | BDU:2019-00966 Уязвимость библиотеки libcurl, связанная с чтением за пределами границ буфера памяти, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 9.8 | 1% Низкий | больше 6 лет назад |
![]() | openSUSE-SU-2019:0174-1 Security update for curl | около 6 лет назад | ||
![]() | openSUSE-SU-2019:0173-1 Security update for curl | больше 6 лет назад | ||
![]() | SUSE-SU-2019:0249-2 Security update for curl | около 6 лет назад | ||
![]() | SUSE-SU-2019:0249-1 Security update for curl | больше 6 лет назад | ||
![]() | SUSE-SU-2019:0248-1 Security update for curl | больше 6 лет назад | ||
ELSA-2019-3701 ELSA-2019-3701: curl security and bug fix update (MODERATE) | больше 5 лет назад | |||
![]() | SUSE-SU-2019:0339-1 Security update for curl | больше 6 лет назад |
Уязвимостей на страницу