CVE-2018-0500
Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including curl 7.60.0 has a heap-based buffer overflow that might be exploitable by an attacker who can control the data that curl transmits over SMTP with certain settings (i.e., use of a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.43%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including curl 7.60.0 has a heap-based buffer overflow that might be exploitable by an attacker who can control the data that curl transmits over SMTP with certain settings (i.e., use of a nonstandard --limit-rate argument or CURLOPT_BUFFERSIZE value).
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 6.43% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- haxx/curl · canonical/ubuntu linux
- Source
- security@debian.org
References
- http://www.securitytracker.com/id/1041280Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:2486Third Party Advisory
- https://curl.haxx.se/docs/adv_2018-70a2.htmlExploit, Patch, Vendor Advisory
- https://github.com/curl/curl/commit/ba1dbd78e5f1ed67c1b8d37ac89d90e5e330b628Patch, Third Party Advisory
- https://security.gentoo.org/glsa/201807-04Third Party Advisory
- https://usn.ubuntu.com/3710-1/Third Party Advisory
- http://www.securitytracker.com/id/1041280Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:2486Third Party Advisory
- https://curl.haxx.se/docs/adv_2018-70a2.htmlExploit, Patch, Vendor Advisory
- https://github.com/curl/curl/commit/ba1dbd78e5f1ed67c1b8d37ac89d90e5e330b628Patch, Third Party Advisory
- https://security.gentoo.org/glsa/201807-04Third Party Advisory
- https://usn.ubuntu.com/3710-1/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.