curl / Docs / Vulnerability table / 7.63.0 vulnerabilities

Vulnerabilities in curl 7.63.0

curl version 7.63.0 was released on December 12 2018. The following 8 security problems are known to exist in this version.

FlawFrom versionTo and includingCVECWE
FTP-KRB double-free7. Double Free
TFTP small blocksize heap buffer overflow7. Heap-based Buffer Overflow
Windows OpenSSL engine code injection7. Code Injection
TFTP receive buffer overflow7. Heap-based Buffer Overflow
Integer overflows in curl_url_set7. Incorrect Calculation of Buffer Size
NTLM type-2 out-of-bounds buffer read7. Out-of-bounds Read
NTLMv2 type-3 header stack buffer overflow7. Stack-based Buffer Overflow
SMTP end-of-response out-of-bounds read7. Out-of-bounds Read

Changelog for curl 7.63.0

See vulnerability summary for the previous release: 7.62.0 or the subsequent release: 7.64.0