[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

[3.4] curl: escape and unescape integer overflows (CVE-2016-7167)

ID: oval:org.secpod.oval:def:1800350Date: (C)2018-03-29   (M)2023-12-20
Class: PATCHFamily: unix




The four libcurl functions curl_escape, curl_easy_escape, curl_unescape and curl_easy_unescape perform string URL percent escaping and unescaping. They accept custom string length inputs in signed integer arguments. Affected versions: libcurl 7.11.1 to and including 7.50.2 Not affected versions: libcurl = 7.50.3.

Platform:
Alpine Linux 3.4
Product:
curl
Reference:
6183
CVE-2016-7167
CVE    1
CVE-2016-7167
CPE    2
cpe:/a:haxx:curl
cpe:/o:alpinelinux:alpine_linux:3.4

© SecPod Technologies