← Back

CVE-2017-1000101

nvd nist
Published: Oct 5, 2017Modified: May 13, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

curl supports "globbing" of URLs, in which a user can pass a numerical range to have the tool iterate over those numbers to do a sequence of transfers. In the globbing function that parses the numerical range, there was an omission that made curl read a byte beyond the end of the URL if given a carefully crafted, or just wrongly written, URL. The URL is stored in a heap based buffer, so it could then be made to wrongly read something else instead of crashing. An example of a URL that triggers the flaw would be `http://ur%20[0-60000000000000000000`.

Affected (32)

Products: Haxx: Curl
1 product
Curl
Configuration A
32 vulnerable
Vulnerable SoftwareAffected Versions
Haxx
Version 7.35.0
Version 7.36.0
Version 7.37.0
Version 7.37.1
Version 7.38.0
Version 7.39.0
Version 7.4.1
Version 7.40.0
Version 7.41.0
Version 7.42.0
Version 7.42.1
Version 7.43.0
Version 7.44.0
Version 7.45.0
Version 7.46.0
Version 7.47.0
Version 7.47.1
Version 7.48.0
Version 7.49.0
Version 7.49.1
Version 7.50.0
Version 7.50.1
Version 7.50.2
Version 7.50.3
Version 7.51.0
Version 7.52.0
Version 7.52.1
Version 7.53.0
Version 7.53.1
Version 7.54.0
Version 7.54.1
Version 7.55.0

References (14)

Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Issue TrackingVendor Advisory
Source: cve@mitre.org
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.