curl / Docs / Vulnerability table / 7.51.0 vulnerabilities

Vulnerabilities in curl 7.51.0

curl version 7.51.0 was released on November 2 2016. The following 16 security problems are known to exist in this version.

FlawFrom versionTo and includingCVECWE
RTSP bad headers buffer over-read7. Buffer Over-read
RTSP RTP buffer over-read7. Buffer Over-read
LDAP NULL pointer dereference7. NULL Pointer Dereference
FTP path trickery leads to NIL byte out of bounds write7. Heap-based Buffer Overflow
HTTP authentication leak in redirects6.07.57.0CVE-2018-1000007CWE-522: Insufficiently Protected Credentials
HTTP/2 trailer out-of-bounds read7. Buffer Over-read
FTP wildcard out of bounds read7. Buffer Over-read
NTLM buffer overflow via integer overflow7. Incorrect Calculation of Buffer Size
IMAP FETCH response out of bounds read7. Buffer Over-read
FTP PWD response parser out of bounds read7.77.55.1CVE-2017-1000254CWE-126: Buffer Over-read
URL globbing out of bounds read7. Buffer Over-read
TFTP sends more than buffer size7. Buffer Over-read
--write-out out of buffer read6.57.53.1CVE-2017-7407CWE-126: Buffer Over-read
printf floating point buffer overflow7.17.51.0CVE-2016-9586CWE-121: Stack-based Buffer Overflow
Win CE schannel cert wildcard matches too much7. Improper Certificate Validation
Win CE schannel cert name out of buffer read7. Buffer Over-read

Changelog for curl 7.51.0

See vulnerability summary for the previous release: 7.50.3 or the subsequent release: 7.52.0