Vulnerabilities in curl 7.57.0

curl version 7.57.0 was released on November 29 2017. The following 9 security problems are known to exist in this version.

FlawFrom versionTo and includingCVECWE
NTLM password overflow via integer overflow7. Incorrect Calculation of Buffer Size
SMTP send heap buffer overflow7. Heap-based Buffer Overflow
FTP shutdown response buffer overflow7. Heap-based Buffer Overflow
RTSP bad headers buffer over-read7. Buffer Over-read
RTSP RTP buffer over-read7. Buffer Over-read
LDAP NULL pointer dereference7. NULL Pointer Dereference
FTP path trickery leads to NIL byte out of bounds write7. Heap-based Buffer Overflow
HTTP authentication leak in redirects6.07.57.0CVE-2018-1000007CWE-522: Insufficiently Protected Credentials
HTTP/2 trailer out-of-bounds read7. Buffer Over-read

