SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-1000122

A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of service or information leakage

CRITICAL 9.1EPSS 9.04%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (9.04%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of service or information leakage

CVSS 3.0
9.1 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS
9.04% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-125
Affected
debian/debian linux · canonical/ubuntu linux · haxx/curl · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation · oracle/communications webrtc session controller · oracle/enterprise manager ops center · oracle/peoplesoft enterprise peopletools
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.