curl / Docs / Vulnerability table / 7.1 vulnerabilities

Vulnerabilities in curl 7.1

curl version 7.1 was released on August 7 2000. The following 17 security problems are known to exist in this version.

FlawFrom versionTo and includingCVE
HTTP authentication leak in redirects6.07.57.0CVE-2018-1000007
--write-out out of buffer read6.57.53.1CVE-2017-7407
printf floating point buffer overflow7.17.51.0CVE-2016-9586
cookie injection for other servers7.17.50.3CVE-2016-8615
OOB write via unchecked multiplication7.17.50.3CVE-2016-8617
double-free in curl_maprintf7.17.50.3CVE-2016-8618
invalid URL parsing with '#'7.17.50.3CVE-2016-8624
TLS session resumption client cert bypass7.17.50.0CVE-2016-5419
Re-using connections with wrong client cert7.17.50.0CVE-2016-5420
sensitive HTTP server headers also sent to proxies7.17.42.0CVE-2015-3153
URL request injection6.07.39.0CVE-2014-8150
cookie leak with IP address as domain7.17.37.1CVE-2014-3613
IP address wildcard certificate validation7.17.35.0CVE-2014-0139
cookie domain tailmatch6.07.29.0CVE-2013-1944
Arbitrary File Access6.07.19.3CVE-2009-0037
Proxy Authentication Header Information Leakage7.17.10.6
FTP Server Response Buffer Overflow6.07.4

Changelog for curl 7.1

See vulnerability summary for the previous release: 6.5.2 or the subsequent release: 7.1.1