curl / Docs / Vulnerability table / 7.13.0 vulnerabilities

Vulnerabilities in curl 7.13.0

curl version 7.13.0 was released on February 1 2005. The following 37 security problems are known to exist in this version.

FlawFrom versionTo and includingCVE
HTTP authentication leak in redirects6.07.57.0CVE-2018-1000007
FTP PWD response parser out of bounds read7.77.55.1CVE-2017-1000254
--write-out out of buffer read6.57.53.1CVE-2017-7407
printf floating point buffer overflow7.17.51.0CVE-2016-9586
cookie injection for other servers7.17.50.3CVE-2016-8615
case insensitive password comparison7.77.50.3CVE-2016-8616
OOB write via unchecked multiplication7.17.50.3CVE-2016-8617
double-free in curl_maprintf7.17.50.3CVE-2016-8618
double-free in krb5 code7.37.50.3CVE-2016-8619
curl_getdate read out of bounds7.12.27.50.3CVE-2016-8621
Use-after-free via shared cookies7.10.77.50.3CVE-2016-8623
invalid URL parsing with '#'7.17.50.3CVE-2016-8624
IDNA 2003 makes curl use wrong host7.12.07.50.3CVE-2016-8625
curl escape and unescape integer overflows7.11.17.50.2CVE-2016-7167
TLS session resumption client cert bypass7.17.50.0CVE-2016-5419
Re-using connections with wrong client cert7.17.50.0CVE-2016-5420
Windows DLL hijacking7.11.17.49.0CVE-2016-4802
NTLM credentials not-checked for proxy connection re-use7.10.77.46.0CVE-2016-0755
sensitive HTTP server headers also sent to proxies7.17.42.0CVE-2015-3153
Negotiate not treated as connection-oriented7.10.67.41.0CVE-2015-3148
Re-using authenticated connection when unauthenticated7.10.67.41.0CVE-2015-3143
URL request injection6.07.39.0CVE-2014-8150
cookie leak with IP address as domain7.17.37.1CVE-2014-3613
IP address wildcard certificate validation7.17.35.0CVE-2014-0139
wrong re-use of connections7.10.77.35.0CVE-2014-0138
re-use of wrong HTTP NTLM connection7.10.67.34.0CVE-2014-0015
URL decode buffer boundary flaw7.77.30.0CVE-2013-2174
cookie domain tailmatch6.07.29.0CVE-2013-1944
SSL CBC IV vulnerability7.10.67.23.1CVE-2011-3389
inappropriate GSSAPI delegation7.10.67.21.6CVE-2011-2192
data callback excessive length7.10.57.19.7CVE-2010-0734
embedded zero in cert name7.47.19.5CVE-2009-2417
Arbitrary File Access6.07.19.3CVE-2009-0037
URL Buffer Overflow7.11.27.15.0CVE-2005-4077
NTLM Buffer Overflow7.10.67.14.1CVE-2005-3185
Kerberos Authentication Buffer Overflow7.37.13.0CVE-2005-0490
NTLM Authentication Buffer Overflow7.10.67.13.0CVE-2005-0490

Changelog for curl 7.13.0

See vulnerability summary for the previous release: 7.12.3 or the subsequent release: 7.13.1