ALT-PU-2016-1971-1
Closed vulnerabilities
Published: 2016-10-07
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2016-7167
Multiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) curl_unescape, and (4) curl_easy_unescape functions in libcurl before 7.50.3 allow attackers to have unspecified impact via a string of length 0xffffffff, which triggers a heap-based buffer overflow.
Severity: CRITICAL (9.8)
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- 92975
- 92975
- 1036813
- 1036813
- SSA:2016-259-01
- SSA:2016-259-01
- RHSA-2017:2016
- RHSA-2017:2016
- RHSA-2018:2486
- RHSA-2018:2486
- RHSA-2018:3558
- RHSA-2018:3558
- https://curl.haxx.se/docs/adv_20160914.html
- https://curl.haxx.se/docs/adv_20160914.html
- [debian-lts-announce] 20181106 [SECURITY] [DLA 1568-1] curl security update
- [debian-lts-announce] 20181106 [SECURITY] [DLA 1568-1] curl security update
- FEDORA-2016-08533fc59c
- FEDORA-2016-08533fc59c
- FEDORA-2016-7a2ed52d41
- FEDORA-2016-7a2ed52d41
- FEDORA-2016-80f4f71eff
- FEDORA-2016-80f4f71eff
- GLSA-201701-47
- GLSA-201701-47