CVE-2018-1000300

Description

curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122: Heap-based Buffer Overflow vulnerability in denial of service and more that can result in curl might overflow a heap based memory buffer when closing down an FTP connection with very long server command replies.. This vulnerability appears to have been fixed in curl < 7.54.1 and curl >= 7.60.0.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.825

Associated Vulnerability

VulnerabilityOS Platform
Vulnerability CVE-2018-1000300,CVE-2018-1000301 are affected in Curl For Windows 7.59.0Windows
Vulnerabilities CVE-2018-1000300,CVE-2018-1000301 are fixed in Curl For Windows 7.60.0Windows
Vulnerabilities CVE-2018-1000300,CVE-2019-2414 are affected in Oracle HTTP Server 12.2.1.3Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.55Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.56Windows
Multiple vulnerabilities are affected in Oracle PeopleSoft Enterprise PeopleTools 8.57Windows
HTTP, HTTPS, and FTP client and client libraries (USN-3648-1) curl_7.55.1-1ubuntu2.5_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-3648-1) curl_7.55.1-1ubuntu2.5_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-3648-1) curl_7.58.0-2ubuntu3.1_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-3648-1) curl_7.58.0-2ubuntu3.1_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-3648-1) libcurl3_7.55.1-1ubuntu2.5_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-3648-1) libcurl3_7.55.1-1ubuntu2.5_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-3648-1) libcurl4_7.58.0-2ubuntu3.1_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-3648-1) libcurl4_7.58.0-2ubuntu3.1_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-3648-1) libcurl3-nss_7.55.1-1ubuntu2.5_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-3648-1) libcurl3-nss_7.55.1-1ubuntu2.5_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-3648-1) libcurl3-nss_7.58.0-2ubuntu3.1_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-3648-1) libcurl3-nss_7.58.0-2ubuntu3.1_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-3648-1) libcurl3-gnutls_7.55.1-1ubuntu2.5_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-3648-1) libcurl3-gnutls_7.55.1-1ubuntu2.5_amd64.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-3648-1) libcurl3-gnutls_7.58.0-2ubuntu3.1_i386.debLinux
HTTP, HTTPS, and FTP client and client libraries (USN-3648-1) libcurl3-gnutls_7.58.0-2ubuntu3.1_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234