[3.4] curl: write-out out of buffer read (CVE-2017-7407)ID: oval:org.secpod.oval:def:1800487 | Date: (C)2018-03-30 (M)2023-12-20 |
Class: PATCH | Family: unix |
There were two bugs in curl"s parser for the command line option --write-out that would skip the end of string zero byte if the string ended in a % or \ , and it would read beyond that buffer in the heap memory and it could then potentially output pieces of that memory to the terminal or the target file etc. Affected versions: 6.5 to and including 7.53.1 Not affected versions: = 7.54.0
Platform: |
Alpine Linux 3.4 |