cbcvebase.
CVE-2014-3707
published 2014-11-15

CVE-2014-3707: The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data…

PriorityP424medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
5.12%
91.3th percentile
The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to read sensitive memory information.

Affected

63 ranges· showing 25
VendorProductVersion rangeFixed in
applemac_os_x
applemac_os_x
applemac_os_x
applemac_os_x
applemac_os_x
appleos_x_yosemite_v10.10.5_and_security_update_2015-006
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiancurl< curl 7.38.0-3 (bookworm)curl 7.38.0-3 (bookworm)
debiandebian_linux
debiandebian_linux
haxxcurl>= 0 < 7.38.0-37.38.0-3
haxxcurl>= 0 < 7.38.0-37.38.0-3
haxxcurl>= 0 < 7.38.0-37.38.0-3
haxxcurl>= 0 < 7.38.0-37.38.0-3
haxxlibcurl
haxxlibcurl
haxxlibcurl
haxxlibcurl
haxxlibcurl
haxxlibcurl
haxxlibcurl
haxxlibcurl

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.