curl / Docs / Vulnerability table / 7.59.0 vulnerabilities

Vulnerabilities in curl 7.59.0

curl version 7.59.0 was released on March 14 2018. The following 7 security problems are known to exist in this version.

FlawFrom versionTo and includingCVECWE
warning message out-of-buffer read7.14.17.61.1CVE-2018-16842CWE-125: Out-of-bounds Read
use-after-free in handle close7.59.07.61.1CVE-2018-16840CWE-416: Use After Free
SASL password overflow via integer overflow7.33.07.61.1CVE-2018-16839CWE-131: Incorrect Calculation of Buffer Size
NTLM password overflow via integer overflow7.15.47.61.0CVE-2018-14618CWE-131: Incorrect Calculation of Buffer Size
SMTP send heap buffer overflow7.54.17.60.0CVE-2018-0500CWE-122: Heap-based Buffer Overflow
FTP shutdown response buffer overflow7.54.17.59.0CVE-2018-1000300CWE-122: Heap-based Buffer Overflow
RTSP bad headers buffer over-read7.20.07.59.0CVE-2018-1000301CWE-126: Buffer Over-read

Changelog for curl 7.59.0

See vulnerability summary for the previous release: 7.58.0 or the subsequent release: 7.60.0