CVE-2018-1000301

CWE-125Out-of-bounds Read11 documents8 sources
Severity
9.1CRITICAL
EPSS
2.8%
top 13.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 24
Latest updateMay 13

Description

curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability appears to have been fixed in curl = 7.60.0.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages8 packages

Also affects: Debian Linux 7.0, 8.0, 9.0, Ubuntu Linux 12.04, 14.04, 16.04, 17.10, 18.04

Patches

🔴Vulnerability Details

4
GHSA
GHSA-32q7-x7q9-wcf9: curl version curl 72022-05-13
OSV
CVE-2018-1000301: curl version curl 72018-05-24
CVEList
CVE-2018-1000301: curl version curl 72018-05-24
OSV
curl vulnerabilities2018-05-16

📋Vendor Advisories

4
Ubuntu
curl vulnerabilities2018-05-24
Ubuntu
curl vulnerabilities2018-05-16
Red Hat
curl: Out-of-bounds heap read when missing RTSP headers allows information leak or denial of service2018-05-16
Debian
CVE-2018-1000301: curl - curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer...2018

💬Community

2
Bugzilla
CVE-2018-1000300 CVE-2018-1000301 curl: various flaws [fedora-all]2018-05-16
Bugzilla
CVE-2018-1000301 curl: Out-of-bounds heap read when missing RTSP headers allows information leak or denial of service2018-05-07
CVE-2018-1000301 (CRITICAL CVSS 9.1) | curl version curl 7.20.0 to and inc | cvebase.io