cbcvebase.
CVE-2017-8816
published 2017-11-29

CVE-2017-8816: The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and…

PriorityP434critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.45%
64.4th percentile
The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vectors involving long user and password fields.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
applemacos_high_sierra_10.13.3_security_update_2018-001_sierra_and_security_update_20
applemacos_high_sierra_10.13.4_security_update_2018-002_sierra_and_security_update_20
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiancurl< curl 7.57.0-1 (bookworm)curl 7.57.0-1 (bookworm)
debiancurl< curl 7.62.0-1 (bookworm)curl 7.62.0-1 (bookworm)
debiandebian_linux
debiandebian_linux
haxxcurl<= 7.56.1
haxxcurl>= 0 < 7.62.0-17.62.0-1
haxxcurl>= 0 < 7.57.0-17.57.0-1
haxxcurl>= 0 < 7.62.0-17.62.0-1
haxxcurl>= 0 < 7.57.0-17.57.0-1
haxxcurl>= 0 < 7.62.0-17.62.0-1
haxxcurl>= 0 < 7.57.0-17.57.0-1
haxxcurl>= 0 < 7.62.0-17.62.0-1
haxxcurl>= 0 < 7.57.0-17.57.0-1
haxxcurl>= 0 < 7.35.0-1ubuntu2.137.35.0-1ubuntu2.13
haxxcurl>= 0 < 7.47.0-1ubuntu2.57.47.0-1ubuntu2.5
haxxlibcurl< 7.61.17.61.1
haxxlibcurl7.36.0 – 7.56.1
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.