CVE-2016-7167Integer Overflow or Wraparound in Libcurl

Severity
9.8CRITICALNVD
OSV7.5
EPSS
2.3%
top 15.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 7
Latest updateMay 14

Description

Multiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) curl_unescape, and (4) curl_easy_unescape functions in libcurl before 7.50.3 allow attackers to have unspecified impact via a string of length 0xffffffff, which triggers a heap-based buffer overflow.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDhaxx/libcurl7.50.2
Debianhaxx/curl< 7.51.0-1+3
Ubuntuhaxx/curl< 7.35.0-1ubuntu2.10+1

Also affects: Fedora 23, 24, 25

🔴Vulnerability Details

4
GHSA
GHSA-679j-c6m7-q7pr: Multiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) curl_unescape, and (4) curl_easy_unescape functions in libcurl before 72022-05-14
OSV
curl vulnerabilities2016-11-03
OSV
CVE-2016-7167: Multiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) curl_unescape, and (4) curl_easy_unescape functions in libcurl before 72016-10-07
CVEList
CVE-2016-7167: Multiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) curl_unescape, and (4) curl_easy_unescape functions in libcurl before 72016-10-07

📋Vendor Advisories

4
Apple
CVE-2016-7167: macOS Sierra 10.12.2, Security Update 2016-003 El Capitan, and Security Update 2016-007 Yosemite2016-12-13
Ubuntu
curl vulnerabilities2016-11-03
Red Hat
curl: escape and unescape integer overflows2016-09-14
Debian
CVE-2016-7167: curl - Multiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) cur...2016

💬Community

4
Bugzilla
CVE-2016-7167 mingw-curl: curl: escape and unescape integer overflows [fedora-all]2016-09-14
Bugzilla
CVE-2016-7167 curl: escape and unescape integer overflows2016-09-14
Bugzilla
CVE-2016-7167 curl: escape and unescape integer overflows [fedora-all]2016-09-14
Bugzilla
CVE-2016-7167 mingw-curl: curl: escape and unescape integer overflows [epel-7]2016-09-14
CVE-2016-7167 — Integer Overflow or Wraparound | cvebase