cbcvebase.
CVE-2015-3144
published 2015-04-24

CVE-2015-3144: The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of…

critical9CVSS 3.1
AVNACLAuSCCICAC
The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
appleos_x_yosemite_v10.10.5_and_security_update_2015-006
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiancurl< curl 7.42.0-1 (bookworm)curl 7.42.0-1 (bookworm)
debiandebian_linux
haxxcurl
haxxcurl
haxxcurl
haxxcurl
haxxcurl
haxxcurl
haxxcurl>= 0 < 7.42.0-17.42.0-1
haxxcurl>= 0 < 7.42.0-17.42.0-1
haxxcurl>= 0 < 7.42.0-17.42.0-1
haxxcurl>= 0 < 7.42.0-17.42.0-1
haxxcurl>= 0 < 7.35.0-1ubuntu2.57.35.0-1ubuntu2.5
haxxlibcurl
haxxlibcurl
haxxlibcurl
haxxlibcurl
haxxlibcurl
haxxlibcurl
oraclemysql_enterprise_monitor<= 2.3.20

CVSS provenance

nvd9.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv9.0CRITICAL