CVE-2024-7264
published 2024-07-31CVE-2024-7264: libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the…
PriorityP343medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
17.30%
96.8th percentile
libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an
ASN.1 Generalized Time field. If given an syntactically incorrect field, the
parser might end up using -1 for the length of the *time fraction*, leading to
a `strlen()` getting performed on a pointer to a heap buffer area that is not
(purposely) null terminated.
This flaw most likely leads to a crash, but can also lead to heap contents
getting returned to the application when
[CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.
Affected
134 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_18.7.3_and_ipados | — | — |
| apple | ios_26.2_and_ipados | — | — |
| apple | macos_sequoia | — | — |
| apple | macos_sonoma | — | — |
| apple | macos_tahoe | — | — |
| apple | tvos | — | — |
| apple | visionos | — | — |
| apple | watchos | — | — |
| curl | curl | 7.32.0 – 7.32.0 | — |
| curl | curl | 7.33.0 – 7.33.0 | — |
| curl | curl | 7.34.0 – 7.34.0 | — |
| curl | curl | 7.35.0 – 7.35.0 | — |
| curl | curl | 7.36.0 – 7.36.0 | — |
| curl | curl | 7.37.0 – 7.37.0 | — |
| curl | curl | 7.37.1 – 7.37.1 | — |
| curl | curl | 7.38.0 – 7.38.0 | — |
| curl | curl | 7.39.0 – 7.39.0 | — |
| curl | curl | 7.40.0 – 7.40.0 | — |
| curl | curl | 7.41.0 – 7.41.0 | — |
| curl | curl | 7.42.0 – 7.42.0 | — |
| curl | curl | 7.42.1 – 7.42.1 | — |
| curl | curl | 7.43.0 – 7.43.0 | — |
| curl | curl | 7.44.0 – 7.44.0 | — |
| curl | curl | 7.45.0 – 7.45.0 | — |
| curl | curl | 7.46.0 – 7.46.0 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2024-7264: macOS Sequoia 15.7.3
vendor_apple·2025-12-12·CVSS 6.5
CVE-2024-7264 [MEDIUM] CVE-2024-7264: macOS Sequoia 15.7.3
Apple Security Update: About the security content of macOS Sequoia 15.7.3
Product: macOS Sequoia
Version: 15.7.3
CVE: CVE-2024-7264
Component: CVE-2024-7264
Apple
CVE-2024-7264: visionOS 26.2
vendor_apple·2025-12-12·CVSS 6.5
CVE-2024-7264 [MEDIUM] CVE-2024-7264: visionOS 26.2
Apple Security Update: About the security content of visionOS 26.2
Product: visionOS
Version: 26.2
CVE: CVE-2024-7264
Component: CVE-2024-7264
Apple
CVE-2024-7264: macOS Sonoma 14.8.3
vendor_apple·2025-12-12·CVSS 6.5
CVE-2024-7264 [MEDIUM] CVE-2024-7264: macOS Sonoma 14.8.3
Apple Security Update: About the security content of macOS Sonoma 14.8.3
Product: macOS Sonoma
Version: 14.8.3
CVE: CVE-2024-7264
Component: CVE-2024-7264
Apple
CVE-2024-7264: macOS Tahoe 26.2
vendor_apple·2025-12-12·CVSS 6.5
CVE-2024-7264 [MEDIUM] CVE-2024-7264: macOS Tahoe 26.2
Apple Security Update: About the security content of macOS Tahoe 26.2
Product: macOS Tahoe
Version: 26.2
CVE: CVE-2024-7264
Component: CVE-2024-7264
Apple
CVE-2024-7264: iOS 18.7.3 and iPadOS 18.7.3
vendor_apple·2025-12-12·CVSS 6.5
CVE-2024-7264 [MEDIUM] CVE-2024-7264: iOS 18.7.3 and iPadOS 18.7.3
Apple Security Update: About the security content of iOS 18.7.3 and iPadOS 18.7.3
Product: iOS 18.7.3 and iPadOS
Version: 18.7.3
CVE: CVE-2024-7264
Component: CVE-2024-7264
Apple
CVE-2024-7264: iOS 26.2 and iPadOS 26.2
vendor_apple·2025-12-12·CVSS 6.5
CVE-2024-7264 [MEDIUM] CVE-2024-7264: iOS 26.2 and iPadOS 26.2
Apple Security Update: About the security content of iOS 26.2 and iPadOS 26.2
Product: iOS 26.2 and iPadOS
Version: 26.2
CVE: CVE-2024-7264
Component: CVE-2024-7264
Apple
CVE-2024-7264: tvOS 26.2
vendor_apple·2025-12-12·CVSS 6.5
CVE-2024-7264 [MEDIUM] CVE-2024-7264: tvOS 26.2
Apple Security Update: About the security content of tvOS 26.2
Product: tvOS
Version: 26.2
CVE: CVE-2024-7264
Component: CVE-2024-7264
Apple
CVE-2024-7264: watchOS 26.2
vendor_apple·2025-12-12·CVSS 6.5
CVE-2024-7264 [MEDIUM] CVE-2024-7264: watchOS 26.2
Apple Security Update: About the security content of watchOS 26.2
Product: watchOS
Version: 26.2
CVE: CVE-2024-7264
Component: CVE-2024-7264
Oracle
Oracle Oracle Communications Applications Risk Matrix: Database (libcurl) — CVE-2024-7264
vendor_oracle·2025-07-15·CVSS 4.5
CVE-2024-7264 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Database (libcurl) — CVE-2024-7264
Oracle Oracle Communications Applications Risk Matrix: Database (libcurl) vulnerability
CVE: CVE-2024-7264
CVSS: 4.5
Protocol: HTTPS
Remote exploit: No
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Oracle
Oracle Oracle Analytics Risk Matrix: Platform Security (curl) — CVE-2024-7264
vendor_oracle·2025-04-15·CVSS 6.5
CVE-2024-7264 [MEDIUM] Oracle Oracle Analytics Risk Matrix: Platform Security (curl) — CVE-2024-7264
Oracle Oracle Analytics Risk Matrix: Platform Security (curl) vulnerability
CVE: CVE-2024-7264
CVSS: 6.5
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Spatial and Graph (libcurl2) — CVE-2024-7264
vendor_oracle·2024-10-15·CVSS 5.3
CVE-2024-7264 [MEDIUM] Oracle Oracle Database Server Risk Matrix: Oracle Spatial and Graph (libcurl2) — CVE-2024-7264
Oracle Oracle Database Server Risk Matrix: Oracle Spatial and Graph (libcurl2) vulnerability
CVE: CVE-2024-7264
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Ubuntu
curl vulnerability
vendor_ubuntu·2024-08-20·CVSS 6.5
CVE-2024-7264 [MEDIUM] curl vulnerability
Title: curl vulnerability
Summary: curl could be made to crash or expose information if it received specially
crafted network traffic.
USN-6944-1 fixed CVE-2024-7264 for Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and
Ubuntu 24.04 LTS. This update provides the corresponding fix for
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.
Original advisory details:
Dov Murik discovered that curl incorrectly handled parsing ASN.1
Generalized Time fields. A remote attacker could use this issue to cause
curl to crash, resulting in a denial of service, or possibly obtain
sensitive memory contents.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
curl vulnerability
vendor_ubuntu·2024-08-05
CVE-2024-7264 curl vulnerability
Title: curl vulnerability
Summary: curl could be made to crash or expose information if it received specially
crafted network traffic.
Dov Murik discovered that curl incorrectly handled parsing ASN.1
Generalized Time fields. A remote attacker could use this issue to cause
curl to crash, resulting in a denial of service, or possibly obtain
sensitive memory contents.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
curl: libcurl: ASN.1 date parser overread
vendor_redhat·2024-07-31·CVSS 6.5
CVE-2024-7264 [MEDIUM] CWE-125 curl: libcurl: ASN.1 date parser overread
curl: libcurl: ASN.1 date parser overread
libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an
ASN.1 Generalized Time field. If given an syntactically incorrect field, the
parser might end up using -1 for the length of the *time fraction*, leading to
a `strlen()` getting performed on a pointer to a heap buffer area that is not
(purposely) null terminated.
This flaw most likely leads to a crash, but can also lead to heap contents
getting returned to the application when
[CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.
A flaw was found in libcurl, where libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If a syntactically incorrect field is given, the parser can use -1 for the
Microsoft
ASN.1 date parser overread
vendor_msrc·2024-07-09·CVSS 6.5
CVE-2024-7264 [MEDIUM] CWE-125 ASN.1 date parser overread
ASN.1 date parser overread
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
curl: curl
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azur
Debian
CVE-2024-7264: curl - libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an A...
vendor_debian·2024·CVSS 6.5
CVE-2024-7264 [MEDIUM] CVE-2024-7264: curl - libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an A...
libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.
Scope: local
bookworm: resolved (fixed in 7.88.1-10+deb12u7)
bullseye: resolved (fixed in 7.74.0-1.3+deb11u13)
forky: resolved (fixed in 8.9.1-1)
sid: resolved (fixed in 8.9.1-1)
trixie: resolved (fixed in 8.9.1-1)
OSV
curl vulnerability
osv·2024-08-20·CVSS 6.5
CVE-2024-7264 [MEDIUM] curl vulnerability
curl vulnerability
USN-6944-1 fixed CVE-2024-7264 for Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and
Ubuntu 24.04 LTS. This update provides the corresponding fix for
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.
Original advisory details:
Dov Murik discovered that curl incorrectly handled parsing ASN.1
Generalized Time fields. A remote attacker could use this issue to cause
curl to crash, resulting in a denial of service, or possibly obtain
sensitive memory contents.
OSV
CVE-2024-7264: libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an
ASN
osv·2024-07-31·CVSS 6.5
CVE-2024-7264 [MEDIUM] CVE-2024-7264: libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an
ASN
libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an
ASN.1 Generalized Time field. If given an syntactically incorrect field, the
parser might end up using -1 for the length of the *time fraction*, leading to
a `strlen()` getting performed on a pointer to a heap buffer area that is not
(purposely) null terminated.
This flaw most likely leads to a crash, but can also lead to heap contents
getting returned to the application when
[CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.
GHSA
GHSA-97c4-2w4v-c7r8: libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an
ASN
ghsa_unreviewed·2024-07-31
CVE-2024-7264 [MEDIUM] CWE-125 GHSA-97c4-2w4v-c7r8: libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an
ASN
libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an
ASN.1 Generalized Time field. If given an syntactically incorrect field, the
parser might end up using -1 for the length of the *time fraction*, leading to
a `strlen()` getting performed on a pointer to a heap buffer area that is not
(purposely) null terminated.
This flaw most likely leads to a crash, but can also lead to heap contents
getting returned to the application when
[CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.
OSV
CVE-2024-7264: libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN
osv·2024-07-31·CVSS 6.5
CVE-2024-7264 [MEDIUM] CVE-2024-7264: libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN
libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.
No detection rules found.
No public exploits indexed.
HackerOne
CVE-2024-7264: ASN.1 date parser overread
hackerone·2024-08-01·CVSS 6.5
CVE-2024-7264 [MEDIUM] CVE-2024-7264: ASN.1 date parser overread
CVE-2024-7264: ASN.1 date parser overread
## Summary:
When a specially-crafted certificate is passed to `Curl_extract_certinfo` to parse, it may read bytes beyond the end of the buffer in which the certificate is held. According to the application, this may be a stack read overflow or a heap read overflow.
Specifically the issue is in function `GTime2str`, in which the specially-crafted input may cause it to set `fracl = -1` and then pass it to `Curl_dyn_addf`, which in turn treats this `-1` as "no length given" and goes on to run `strlen(tzp)` which goes beyond the end of the certificate buffer (assuming there are no null bytes).
I believe the issue is in this loop (in `lib/vtls/x509asn1.c`):
```
524 /* Strip leading zeroes in fractional seconds. */
525 for(fracl = tzp - fracp - 1; f
Bugzilla
CVE-2024-7264 curl: libcurl: ASN.1 date parser overread
bugzilla·2024-07-31·CVSS 6.5
CVE-2024-7264 [MEDIUM] CVE-2024-7264 curl: libcurl: ASN.1 date parser overread
CVE-2024-7264 curl: libcurl: ASN.1 date parser overread
libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated.
This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when
CURLINFO_CERTINFO (https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.
Discussion:
This issue has been addressed in the following products:
Red Hat OpenShift Service Mesh 2.6 for RHEL 8
Red Hat OpenShift Service Mesh 2.6 for RHEL 9
Via RHSA-2024:7726 https://access.redhat.
http://www.openwall.com/lists/oss-security/2024/07/31/1https://curl.se/docs/CVE-2024-7264.htmlhttps://curl.se/docs/CVE-2024-7264.jsonhttps://hackerone.com/reports/2629968http://www.openwall.com/lists/oss-security/2024/07/31/1https://github.com/curl/curl/commit/27959ecce75cdb2809c0bdb3286e60e08fadb519https://security.netapp.com/advisory/ntap-20240828-0008/https://security.netapp.com/advisory/ntap-20241025-0006/https://security.netapp.com/advisory/ntap-20241025-0010/
2024-07-31
Published