CVE-2010-0734
published 2010-03-19CVE-2010-0734: content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that…
PriorityP428medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
5.48%
90.5th percentile
content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that requests automatic decompression, which might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact by sending crafted compressed data to an application that relies on the intended data-length limit.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
| curl | libcurl | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
libcURL up to 7.19.7 content_encoding.c access control (Nessus ID 68025 / ID 216009)
vuldb·2026-05-03·CVSS 6.8
CVE-2010-0734 [MEDIUM] libcURL up to 7.19.7 content_encoding.c access control (Nessus ID 68025 / ID 216009)
A vulnerability labeled as problematic has been found in libcURL. Affected by this vulnerability is an unknown functionality of the file content_encoding.c. The manipulation results in improper access controls.
This vulnerability is reported as CVE-2010-0734. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
GHSA
GHSA-65fc-r6mj-6v9j: content_encoding
ghsa_unreviewed·2022-05-02
CVE-2010-0734 [MEDIUM] GHSA-65fc-r6mj-6v9j: content_encoding
content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that requests automatic decompression, which might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact by sending crafted compressed data to an application that relies on the intended data-length limit.
OSV
CVE-2010-0734: content_encoding
osv·2010-03-19·CVSS 6.8
CVE-2010-0734 [MEDIUM] CVE-2010-0734: content_encoding
content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that requests automatic decompression, which might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact by sending crafted compressed data to an application that relies on the intended data-length limit.
Ubuntu
curl vulnerabilities
vendor_ubuntu·2011-06-24·CVSS 7.5
CVE-2009-2417 [HIGH] curl vulnerabilities
Title: curl vulnerabilities
Summary: Multiple vulnerabilities in curl.
Richard Silverman discovered that when doing GSSAPI authentication,
libcurl unconditionally performs credential delegation, handing the
server a copy of the client's security credential. (CVE-2011-2192)
Wesley Miaw discovered that when zlib is enabled, libcurl does not
properly restrict the amount of callback data sent to an application
that requests automatic decompression. This might allow an attacker to
cause a denial of service via an application crash or possibly execute
arbitrary code with the privilege of the application. This issue only
affected Ubuntu 8.04 LTS and Ubuntu 10.04 LTS. (CVE-2010-0734)
USN 818-1 fixed an issue with curl's handling of SSL certificates with
zero bytes in the Common Name. Due to a
VMware
Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX
vendor_vmware·2011-02-10·CVSS 5.0
CVE-2008-0085 [MEDIUM] Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX
VMSA-2011-0003: Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX
Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX VMware Security Advisory VMware Security Advisory Advisory ID: VMware Security Advisory Synopsis: Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX VMware Security Advisory Issue date: VMware Security Advisory Updated on: VMware Security Advisory CVE numbers:
CVEs: CVE-2008-0085, CVE-2008-0086, CVE-2008-0106, CVE-2008-0107, CVE-2008-3825, CVE-2008-5416, CVE-2009-1384, CVE-2009-2693, CVE-2009-2901, CVE-2009-2902, CVE-2009-3548, CVE-2009-3555, CVE-2009-4308, CVE-2010-0003, CVE-2010-0007, CVE-2010-0008, CVE-2010-0082, CVE-2010-0084, CVE-2010-0085,
Red Hat
curl: zlib-compression causes curl to pass more than CURL_MAX_WRITE_SIZE bytes to write callback
vendor_redhat·2010-02-09·CVSS 6.8
CVE-2010-0734 [MEDIUM] curl: zlib-compression causes curl to pass more than CURL_MAX_WRITE_SIZE bytes to write callback
curl: zlib-compression causes curl to pass more than CURL_MAX_WRITE_SIZE bytes to write callback
content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that requests automatic decompression, which might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact by sending crafted compressed data to an application that relies on the intended data-length limit.
Debian
CVE-2010-0734: curl - content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does ...
vendor_debian·2010·CVSS 6.8
CVE-2010-0734 [MEDIUM] CVE-2010-0734: curl - content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does ...
content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that requests automatic decompression, which might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact by sending crafted compressed data to an application that relies on the intended data-length limit.
Scope: local
bookworm: resolved (fixed in 7.20.0-1)
bullseye: resolved (fixed in 7.20.0-1)
forky: resolved (fixed in 7.20.0-1)
sid: resolved (fixed in 7.20.0-1)
trixie: resolved (fixed in 7.20.0-1)
No detection rules found.
No public exploits indexed.
http://curl.haxx.se/docs/adv_20100209.htmlhttp://curl.haxx.se/docs/security.html#20100209http://curl.haxx.se/libcurl-contentencoding.patchhttp://lists.apple.com/archives/security-announce/2010//Jun/msg00001.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/036744.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/037143.htmlhttp://secunia.com/advisories/38843http://secunia.com/advisories/38981http://secunia.com/advisories/39087http://secunia.com/advisories/39734http://secunia.com/advisories/40220http://secunia.com/advisories/45047http://secunia.com/advisories/48256http://security.gentoo.org/glsa/glsa-201203-02.xmlhttp://support.apple.com/kb/HT4188http://support.avaya.com/css/P8/documents/100081819http://wiki.rpath.com/Advisories:rPSA-2010-0072http://www.debian.org/security/2010/dsa-2023http://www.mandriva.com/security/advisories?name=MDVSA-2010:062http://www.openwall.com/lists/oss-security/2010/02/09/5http://www.openwall.com/lists/oss-security/2010/03/09/1http://www.openwall.com/lists/oss-security/2010/03/16/11http://www.redhat.com/support/errata/RHSA-2010-0329.htmlhttp://www.securityfocus.com/archive/1/514490/100/0/threadedhttp://www.securityfocus.com/archive/1/516397/100/0/threadedhttp://www.ubuntu.com/usn/USN-1158-1http://www.vmware.com/security/advisories/VMSA-2011-0003.htmlhttp://www.vupen.com/english/advisories/2010/0571http://www.vupen.com/english/advisories/2010/0602http://www.vupen.com/english/advisories/2010/0660http://www.vupen.com/english/advisories/2010/0725http://www.vupen.com/english/advisories/2010/1481https://bugzilla.redhat.com/show_bug.cgi?id=563220https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10760https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6756http://curl.haxx.se/docs/adv_20100209.htmlhttp://curl.haxx.se/docs/security.html#20100209http://curl.haxx.se/libcurl-contentencoding.patchhttp://lists.apple.com/archives/security-announce/2010//Jun/msg00001.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/036744.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-March/037143.htmlhttp://secunia.com/advisories/38843http://secunia.com/advisories/38981http://secunia.com/advisories/39087http://secunia.com/advisories/39734http://secunia.com/advisories/40220http://secunia.com/advisories/45047http://secunia.com/advisories/48256http://security.gentoo.org/glsa/glsa-201203-02.xmlhttp://support.apple.com/kb/HT4188http://support.avaya.com/css/P8/documents/100081819http://wiki.rpath.com/Advisories:rPSA-2010-0072http://www.debian.org/security/2010/dsa-2023http://www.mandriva.com/security/advisories?name=MDVSA-2010:062http://www.openwall.com/lists/oss-security/2010/02/09/5http://www.openwall.com/lists/oss-security/2010/03/09/1http://www.openwall.com/lists/oss-security/2010/03/16/11http://www.redhat.com/support/errata/RHSA-2010-0329.htmlhttp://www.securityfocus.com/archive/1/514490/100/0/threadedhttp://www.securityfocus.com/archive/1/516397/100/0/threadedhttp://www.ubuntu.com/usn/USN-1158-1http://www.vmware.com/security/advisories/VMSA-2011-0003.htmlhttp://www.vupen.com/english/advisories/2010/0571http://www.vupen.com/english/advisories/2010/0602http://www.vupen.com/english/advisories/2010/0660http://www.vupen.com/english/advisories/2010/0725http://www.vupen.com/english/advisories/2010/1481https://bugzilla.redhat.com/show_bug.cgi?id=563220https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10760https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6756
2010-03-19
Published