curl / Docs / Vulnerability table / 7.42.1 vulnerabilities

Vulnerabilities in curl 7.42.1

curl version 7.42.1 was released on April 29 2015. The following 26 security problems are known to exist in this version.

FlawFrom versionTo and includingCVE
--write-out out of buffer read6.57.53.1CVE-2017-7407
printf floating point buffer overflow7.17.51.0CVE-2016-9586
Win CE schannel cert wildcard matches too much7.30.07.51.0CVE-2016-9952
Win CE schannel cert name out of buffer read7.30.07.51.0CVE-2016-9953
cookie injection for other servers7.17.50.3CVE-2016-8615
case insensitive password comparison7.77.50.3CVE-2016-8616
OOB write via unchecked multiplication7.17.50.3CVE-2016-8617
double-free in curl_maprintf7.17.50.3CVE-2016-8618
double-free in krb5 code7.37.50.3CVE-2016-8619
glob parser write/read out of bounds7.34.07.50.3CVE-2016-8620
curl_getdate read out of bounds7.12.27.50.3CVE-2016-8621
URL unescape heap overflow via integer truncation7.24.07.50.3CVE-2016-8622
Use-after-free via shared cookies7.10.77.50.3CVE-2016-8623
invalid URL parsing with '#'7.17.50.3CVE-2016-8624
IDNA 2003 makes curl use wrong host7.12.07.50.3CVE-2016-8625
curl escape and unescape integer overflows7.11.17.50.2CVE-2016-7167
Incorrect reuse of client certificates7.19.67.50.1CVE-2016-7141
TLS session resumption client cert bypass7.17.50.0CVE-2016-5419
Re-using connections with wrong client cert7.17.50.0CVE-2016-5420
use of connection struct after free7.32.07.50.0CVE-2016-5421
Windows DLL hijacking7.11.17.49.0CVE-2016-4802
TLS certificate check bypass with mbedTLS/PolarSSL7.21.07.48.0CVE-2016-3739
remote file name path traversal in curl tool for Windows7.20.07.46.0CVE-2016-0754
NTLM credentials not-checked for proxy connection re-use7.10.77.46.0CVE-2016-0755
SMB send off unrelated memory contents7.40.07.42.1CVE-2015-3237
lingering HTTP credentials in connection re-use7.40.07.42.1CVE-2015-3236

Changelog for curl 7.42.1

See vulnerability summary for the previous release: 7.42.0 or the subsequent release: 7.43.0