curl / Docs / Vulnerability table / 7.37.0 vulnerabilities

Vulnerabilities in curl 7.37.0

curl version 7.37.0 was released on May 21 2014. The following 33 security problems are known to exist in this version.

FlawFrom versionTo and includingCVE
printf floating point buffer overflow7.17.51.0CVE-2016-9586
Win CE schannel cert wildcard matches too much7.30.07.51.0CVE-2016-9952
Win CE schannel cert name out of buffer read7.30.07.51.0CVE-2016-9953
cookie injection for other servers7.17.50.3CVE-2016-8615
case insensitive password comparison7.77.50.3CVE-2016-8616
OOB write via unchecked multiplication7.17.50.3CVE-2016-8617
double-free in curl_maprintf7.17.50.3CVE-2016-8618
double-free in krb5 code7.37.50.3CVE-2016-8619
glob parser write/read out of bounds7.34.07.50.3CVE-2016-8620
curl_getdate read out of bounds7.12.27.50.3CVE-2016-8621
URL unescape heap overflow via integer truncation7.24.07.50.3CVE-2016-8622
Use-after-free via shared cookies7.10.77.50.3CVE-2016-8623
invalid URL parsing with '#'7.17.50.3CVE-2016-8624
IDNA 2003 makes curl use wrong host7.12.07.50.3CVE-2016-8625
curl escape and unescape integer overflows7.11.17.50.2CVE-2016-7167
Incorrect reuse of client certificates7.19.67.50.1CVE-2016-7141
TLS session resumption client cert bypass7.17.50.0CVE-2016-5419
Re-using connections with wrong client cert7.17.50.0CVE-2016-5420
use of connection struct after free7.32.07.50.0CVE-2016-5421
Windows DLL hijacking7.11.17.49.0CVE-2016-4802
TLS certificate check bypass with mbedTLS/PolarSSL7.21.07.48.0CVE-2016-3739
remote file name path traversal in curl tool for Windows7.20.07.46.0CVE-2016-0754
NTLM credentials not-checked for proxy connection re-use7.10.77.46.0CVE-2016-0755
sensitive HTTP server headers also sent to proxies7.17.42.0CVE-2015-3153
host name out of boundary memory access7.37.07.41.0CVE-2015-3144
cookie parser out of boundary memory access7.31.07.41.0CVE-2015-3145
Negotiate not treated as connection-oriented7.10.67.41.0CVE-2015-3148
Re-using authenticated connection when unauthenticated7.10.67.41.0CVE-2015-3143
darwinssl certificate check bypass7.31.07.39.0CVE-2014-8151
URL request injection6.07.39.0CVE-2014-8150
duphandle read out of bounds7.17.17.38.0CVE-2014-3707
cookie leak for TLDs7.31.07.37.1CVE-2014-3620
cookie leak with IP address as domain7.17.37.1CVE-2014-3613

Changelog for curl 7.37.0

See vulnerability summary for the previous release: 7.36.0 or the subsequent release: 7.37.1