curl / Docs / Vulnerability table / 7.50.2 vulnerabilities

Vulnerabilities in curl 7.50.2

curl version 7.50.2 was released on September 7 2016. The following 24 security problems are known to exist in this version.

FlawFrom versionTo and includingCVE
HTTP authentication leak in redirects6.07.57.0CVE-2018-1000007
HTTP/2 trailer out-of-bounds read7.49.07.57.0CVE-2018-1000005
FTP wildcard out of bounds read7.21.07.56.1CVE-2017-8817
NTLM buffer overflow via integer overflow7.36.07.56.1CVE-2017-8816
IMAP FETCH response out of bounds read7.20.07.56.0CVE-2017-1000257
FTP PWD response parser out of bounds read7.77.55.1CVE-2017-1000254
URL globbing out of bounds read7.34.07.54.1CVE-2017-1000101
TFTP sends more than buffer size7.15.07.54.1CVE-2017-1000100
--write-out out of buffer read6.57.53.1CVE-2017-7407
printf floating point buffer overflow7.17.51.0CVE-2016-9586
Win CE schannel cert wildcard matches too much7.30.07.51.0CVE-2016-9952
Win CE schannel cert name out of buffer read7.30.07.51.0CVE-2016-9953
cookie injection for other servers7.17.50.3CVE-2016-8615
case insensitive password comparison7.77.50.3CVE-2016-8616
OOB write via unchecked multiplication7.17.50.3CVE-2016-8617
double-free in curl_maprintf7.17.50.3CVE-2016-8618
double-free in krb5 code7.37.50.3CVE-2016-8619
glob parser write/read out of bounds7.34.07.50.3CVE-2016-8620
curl_getdate read out of bounds7.12.27.50.3CVE-2016-8621
URL unescape heap overflow via integer truncation7.24.07.50.3CVE-2016-8622
Use-after-free via shared cookies7.10.77.50.3CVE-2016-8623
invalid URL parsing with '#'7.17.50.3CVE-2016-8624
IDNA 2003 makes curl use wrong host7.12.07.50.3CVE-2016-8625
curl escape and unescape integer overflows7.11.17.50.2CVE-2016-7167

Changelog for curl 7.50.2

See vulnerability summary for the previous release: 7.50.1 or the subsequent release: 7.50.3