CVE-2018-0500Out-of-bounds Write in Curl

Severity
9.8CRITICALNVD
EPSS
1.2%
top 21.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 11
Latest updateMay 13

Description

Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including curl 7.60.0 has a heap-based buffer overflow that might be exploitable by an attacker who can control the data that curl transmits over SMTP with certain settings (i.e., use of a nonstandard --limit-rate argument or CURLOPT_BUFFERSIZE value).

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

Debianhaxx/curl< 7.61.0-1+3
NVDhaxx/curl7.54.17.60.0

Also affects: Ubuntu Linux 17.10, 18.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-rg4c-f6cj-x9w8: Curl_smtp_escape_eob in lib/smtp2022-05-13
OSV
CVE-2018-0500: Curl_smtp_escape_eob in lib/smtp2018-07-11
CVEList
CVE-2018-0500: Curl_smtp_escape_eob in lib/smtp2018-07-11

📋Vendor Advisories

3
Ubuntu
curl vulnerability2018-07-11
Red Hat
curl: Heap-based buffer overflow in Curl_smtp_escape_eob() when uploading data over SMTP2018-07-11
Debian
CVE-2018-0500: curl - Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including curl 7.60.0 h...2018

💬Community

2
Bugzilla
CVE-2018-0500 curl: Heap-based buffer overflow in Curl_smtp_escape_eob() when uploading data over SMTP [fedora-all]2018-07-11
Bugzilla
CVE-2018-0500 curl: Heap-based buffer overflow in Curl_smtp_escape_eob() when uploading data over SMTP2018-07-02
CVE-2018-0500 — Out-of-bounds Write in Haxx Curl | cvebase