cbcvebase.

Debian Curl vulnerabilities

165 known vulnerabilities affecting debian/curl.

Total CVEs
165
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL23HIGH36MEDIUM65LOW41

Vulnerabilities

Page 2 of 9
CVE-2023-27533P3HIGHCVSS 8.8fixed in curl 7.88.1-7 (bookworm)2023
CVE-2023-27533 [HIGH] CVE-2023-27533: curl - A vulnerability in input validation exists in curl <8.0 during communication usi... A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application's intent. This vulnerability coul
debian
CVE-2016-5420P3HIGHCVSS 7.5fixed in curl 7.50.1-1 (bookworm)2016
CVE-2016-5420 [HIGH] CVE-2016-5420: curl - curl and libcurl before 7.50.1 do not check the client certificate when choosing... curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously created connection with a different client certificate. Scope: local bookworm: resolved (fixed in 7.50.1-1) bullseye: resolved (fixed in 7.50.1-1) forky:
debian
CVE-2016-7167P3CRITICALCVSS 9.8fixed in curl 7.51.0-1 (bookworm)2016
CVE-2016-7167 [CRITICAL] CVE-2016-7167: curl - Multiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) cur... Multiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) curl_unescape, and (4) curl_easy_unescape functions in libcurl before 7.50.3 allow attackers to have unspecified impact via a string of length 0xffffffff, which triggers a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 7.51.0-1) bullseye: resolved (fixed in 7.51.0-1) f
debian
CVE-2019-5481P3CRITICALCVSS 9.8fixed in curl 7.66.0-1 (bookworm)2019
CVE-2019-5481 [CRITICAL] CVE-2019-5481: curl - Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3. Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3. Scope: local bookworm: resolved (fixed in 7.66.0-1) bullseye: resolved (fixed in 7.66.0-1) forky: resolved (fixed in 7.66.0-1) sid: resolved (fixed in 7.66.0-1) trixie: resolved (fixed in 7.66.0-1)
debian
CVE-2018-1000300P3CRITICALCVSS 9.8fixed in curl 7.60.0-1 (bookworm)2018
CVE-2018-1000300 [CRITICAL] CVE-2018-1000300: curl - curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122: Heap-b... curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122: Heap-based Buffer Overflow vulnerability in denial of service and more that can result in curl might overflow a heap based memory buffer when closing down an FTP connection with very long server command replies.. This vulnerability appears to have been fixed in curl = 7.60.0. Scope: local
debian
CVE-2022-42915P3HIGHCVSS 8.1fixed in curl 7.86.0-1 (bookworm)2022
CVE-2022-42915 [HIGH] CVE-2022-42915: curl - curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a... curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it sets up the connection to the remote server by issuing a CONNECT request to the proxy, and then tunnels the rest of the protocol through. An HTTP proxy might refuse this request (HTTP proxies often only allow outgoing connections to specific port numbers
debian
CVE-2018-16839P3MEDIUMCVSS 4.3fixed in curl 7.62.0-1 (bookworm)2018
CVE-2018-16839 [MEDIUM] CVE-2018-16839: curl - Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun in the SA... Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun in the SASL authentication code that may lead to denial of service. Scope: local bookworm: resolved (fixed in 7.62.0-1) bullseye: resolved (fixed in 7.62.0-1) forky: resolved (fixed in 7.62.0-1) sid: resolved (fixed in 7.62.0-1) trixie: resolved (fixed in 7.62.0-1)
debian
CVE-2022-22576P3HIGHCVSS 8.1fixed in curl 7.83.0-1 (bookworm)2022
CVE-2022-22576 [HIGH] CVE-2022-22576: curl - An improper authentication vulnerability exists in curl 7.33.0 to and including ... An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only). Scope: local bo
debian
CVE-2022-32206P3MEDIUMCVSS 6.5fixed in curl 7.84.0-1 (bookworm)2022
CVE-2022-32206 [MEDIUM] CVE-2022-32206: curl - curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a ser... curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a decompression cha
debian
CVE-2012-0036P3HIGHCVSS 7.5fixed in curl 7.24.0-1 (bookworm)2012
CVE-2012-0036 [HIGH] CVE-2012-0036: curl - curl and libcurl 7.2x before 7.24.0 do not properly consider special characters ... curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows remote attackers to conduct data-injection attacks via a crafted URL, as demonstrated by a CRLF injection attack on the (1) IMAP, (2) POP3, or (3) SMTP protocol. Scope: local bookworm: resolved (fixed in 7.24.0-1) bullseye: resolved (fi
debian
CVE-2020-8285P3HIGHCVSS 7.5fixed in curl 7.74.0-1 (bookworm)2020
CVE-2020-8285 [HIGH] CVE-2020-8285: curl - curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due ... curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing. Scope: local bookworm: resolved (fixed in 7.74.0-1) bullseye: resolved (fixed in 7.74.0-1) forky: resolved (fixed in 7.74.0-1) sid: resolved (fixed in 7.74.0-1) trixie: resolved (fixed in 7.74.0-1)
debian
CVE-2016-7141P3HIGHCVSS 7.5fixed in curl 7.51.0-1 (bookworm)2016
CVE-2016-7141 [HIGH] CVE-2016-7141: curl - curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library... curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420. Scope: local bookworm
debian
CVE-2021-22946P3HIGHCVSS 7.5fixed in curl 7.79.1-1 (bookworm)2021
CVE-2021-22946 [HIGH] CVE-2021-22946: curl - A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to ... A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate response.This flaw w
debian
CVE-2018-1000122P3CRITICALCVSS 9.1fixed in curl 7.60.0-1 (bookworm)2018
CVE-2018-1000122 [CRITICAL] CVE-2018-1000122: curl - A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTS... A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of service or information leakage Scope: local bookworm: resolved (fixed in 7.60.0-1) bullseye: resolved (fixed in 7.60.0-1) forky: resolved (fixed in 7.60.0-1) sid: resolved (fixed in 7.60.0-1) trixie: resolved (fixed in
debian
CVE-2016-0755P3MEDIUMCVSS 4.0fixed in curl 7.47.0-1 (bookworm)2016
CVE-2016-0755 [MEDIUM] CVE-2016-0755: curl - The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not pro... The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users via a request, a similar issue to CVE-2014-0015. Scope: local bookworm: resolved (fixed in 7.47.0-1) bullseye: resolved (fixed in 7.47.0-1) forky: resolved (fixed in 7.47.0-1
debian
CVE-2016-5421P3HIGHCVSS 8.1fixed in curl 7.50.1-1 (bookworm)2016
CVE-2016-5421 [HIGH] CVE-2016-5421: curl - Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to contro... Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact via unknown vectors. Scope: local bookworm: resolved (fixed in 7.50.1-1) bullseye: resolved (fixed in 7.50.1-1) forky: resolved (fixed in 7.50.1-1) sid: resolved (fixed in 7.50.1-1) trixie: resolved (fixed in 7.50.1-1)
debian
CVE-2018-1000005P3CRITICALCVSS 9.1fixed in curl 7.58.0-1 (bookworm)2018
CVE-2018-1000005 [CRITICAL] CVE-2018-1000005: curl - libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handl... libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers. It was reported (https://github.com/curl/curl/pull/2231) that reading an HTTP/2 trailer could mess up future trailers since the stored size was one byte less than required. The problem is that the code that creates HTTP/1-like headers from the HTTP/2 trailer dat
debian
CVE-2017-8816P3CRITICALCVSS 9.8fixed in curl 7.57.0-1 (bookworm)2017
CVE-2017-8816 [CRITICAL] CVE-2017-8816: curl - The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit plat... The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vectors involving long user and password fields. Scope: local bookworm: resolved (fixed in 7.57.0-1) bullseye: resolved
debian
CVE-2016-8618P3MEDIUMCVSS 5.3fixed in curl 7.51.0-1 (bookworm)2016
CVE-2016-8618 [MEDIUM] CVE-2016-8618: curl - The libcurl API function called `curl_maprintf()` before version 7.51.0 can be t... The libcurl API function called `curl_maprintf()` before version 7.51.0 can be tricked into doing a double-free due to an unsafe `size_t` multiplication, on systems using 32 bit `size_t` variables. Scope: local bookworm: resolved (fixed in 7.51.0-1) bullseye: resolved (fixed in 7.51.0-1) forky: resolved (fixed in 7.51.0-1) sid: resolved (fixed in 7.51.0-1) trixie: reso
debian
CVE-2017-8817P3CRITICALCVSS 9.8fixed in curl 7.57.0-1 (bookworm)2017
CVE-2017-8817 [CRITICAL] CVE-2017-8817: curl - The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attack... The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a string that ends with an '[' character. Scope: local bookworm: resolved (fixed in 7.57.0-1) bullseye: resolved (fixed in 7.57.0-1) forky: resolved (fixed in 7.57.0-1
debian
Debian Curl vulnerabilities | cvebase