curl / Docs / Vulnerability table / 7.1.1 vulnerabilities

Vulnerabilities in curl 7.1.1

curl version 7.1.1 was released on August 21 2000. The following 17 security problems are known to exist in this version.

FlawFrom versionTo and includingCVE
HTTP authentication leak in redirects6.07.57.0CVE-2018-1000007
--write-out out of buffer read6.57.53.1CVE-2017-7407
printf floating point buffer overflow7.17.51.0CVE-2016-9586
cookie injection for other servers7.17.50.3CVE-2016-8615
OOB write via unchecked multiplication7.17.50.3CVE-2016-8617
double-free in curl_maprintf7.17.50.3CVE-2016-8618
invalid URL parsing with '#'7.17.50.3CVE-2016-8624
TLS session resumption client cert bypass7.17.50.0CVE-2016-5419
Re-using connections with wrong client cert7.17.50.0CVE-2016-5420
sensitive HTTP server headers also sent to proxies7.17.42.0CVE-2015-3153
URL request injection6.07.39.0CVE-2014-8150
cookie leak with IP address as domain7.17.37.1CVE-2014-3613
IP address wildcard certificate validation7.17.35.0CVE-2014-0139
cookie domain tailmatch6.07.29.0CVE-2013-1944
Arbitrary File Access6.07.19.3CVE-2009-0037
Proxy Authentication Header Information Leakage7.17.10.6
FTP Server Response Buffer Overflow6.07.4

Changelog for curl 7.1.1

See vulnerability summary for the previous release: 7.1 or the subsequent release: 7.2