curl / Docs / Vulnerability table / 7.57.0 vulnerabilities

Vulnerabilities in curl 7.57.0

curl version 7.57.0 was released on November 29 2017. The following 8 security problems are known to exist in this version.

FlawFrom versionTo and includingCVECWE
SMTP send heap buffer overflow7.54.17.60.0CVE-2018-0500CWE-122: Heap-based Buffer Overflow
FTP shutdown response buffer overflow7.54.17.59.0CVE-2018-1000300CWE-122: Heap-based Buffer Overflow
RTSP bad headers buffer over-read7.20.07.59.0CVE-2018-1000301CWE-126: Buffer Over-read
RTSP RTP buffer over-read7.20.07.58.0CVE-2018-1000122CWE-126: Buffer Over-read
LDAP NULL pointer dereference7.21.07.58.0CVE-2018-1000121CWE-476: NULL Pointer Dereference
FTP path trickery leads to NIL byte out of bounds write7.12.37.58.0CVE-2018-1000120CWE-122: Heap-based Buffer Overflow
HTTP authentication leak in redirects6.07.57.0CVE-2018-1000007CWE-522: Insufficiently Protected Credentials
HTTP/2 trailer out-of-bounds read7.49.07.57.0CVE-2018-1000005CWE-126: Buffer Over-read

Changelog for curl 7.57.0

See vulnerability summary for the previous release: 7.56.1 or the subsequent release: 7.58.0