curl / Docs / Vulnerability table / 7.15.2 vulnerabilities

Vulnerabilities in curl 7.15.2

curl version 7.15.2 was released on February 27 2006. The following 36 security problems are known to exist in this version.

FlawFrom versionTo and includingCVE
HTTP authentication leak in redirects6.07.57.0CVE-2018-1000007
FTP PWD response parser out of bounds read7.77.55.1CVE-2017-1000254
TFTP sends more than buffer size7.15.07.54.1CVE-2017-1000100
--write-out out of buffer read6.57.53.1CVE-2017-7407
printf floating point buffer overflow7.17.51.0CVE-2016-9586
cookie injection for other servers7.17.50.3CVE-2016-8615
case insensitive password comparison7.77.50.3CVE-2016-8616
OOB write via unchecked multiplication7.17.50.3CVE-2016-8617
double-free in curl_maprintf7.17.50.3CVE-2016-8618
double-free in krb5 code7.37.50.3CVE-2016-8619
curl_getdate read out of bounds7.12.27.50.3CVE-2016-8621
Use-after-free via shared cookies7.10.77.50.3CVE-2016-8623
invalid URL parsing with '#'7.17.50.3CVE-2016-8624
IDNA 2003 makes curl use wrong host7.12.07.50.3CVE-2016-8625
curl escape and unescape integer overflows7.11.17.50.2CVE-2016-7167
TLS session resumption client cert bypass7.17.50.0CVE-2016-5419
Re-using connections with wrong client cert7.17.50.0CVE-2016-5420
Windows DLL hijacking7.11.17.49.0CVE-2016-4802
NTLM credentials not-checked for proxy connection re-use7.10.77.46.0CVE-2016-0755
sensitive HTTP server headers also sent to proxies7.17.42.0CVE-2015-3153
Negotiate not treated as connection-oriented7.10.67.41.0CVE-2015-3148
Re-using authenticated connection when unauthenticated7.10.67.41.0CVE-2015-3143
URL request injection6.07.39.0CVE-2014-8150
cookie leak with IP address as domain7.17.37.1CVE-2014-3613
IP address wildcard certificate validation7.17.35.0CVE-2014-0139
wrong re-use of connections7.10.77.35.0CVE-2014-0138
re-use of wrong HTTP NTLM connection7.10.67.34.0CVE-2014-0015
URL decode buffer boundary flaw7.77.30.0CVE-2013-2174
cookie domain tailmatch6.07.29.0CVE-2013-1944
SSL CBC IV vulnerability7.10.67.23.1CVE-2011-3389
inappropriate GSSAPI delegation7.10.67.21.6CVE-2011-2192
data callback excessive length7.10.57.19.7CVE-2010-0734
embedded zero in cert name7.47.19.5CVE-2009-2417
Arbitrary File Access6.07.19.3CVE-2009-0037
GnuTLS insufficient cert verification7.14.07.16.3CVE-2007-3564
TFTP Packet Buffer Overflow7.15.07.15.2CVE-2006-1061

Changelog for curl 7.15.2

See vulnerability summary for the previous release: 7.15.1 or the subsequent release: 7.15.3