← Retour aux CVEs
CVE-2018-16839
N/ADescription
Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun in the SASL authentication code that may lead to denial of service.
Details CVE
Score CVSS v3.1N/A
Publie10/31/2018
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
canonical:ubuntu_linuxdebian:debian_linuxhaxx:curl
Faiblesses (CWE)
CWE-122CWE-190CWE-119
References
http://www.securitytracker.com/id/1042012(secalert@redhat.com)
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16839(secalert@redhat.com)
https://curl.haxx.se/docs/CVE-2018-16839.html(secalert@redhat.com)
https://github.com/curl/curl/commit/f3a24d7916b9173c69a3e0ee790102993833d6c5(secalert@redhat.com)
https://lists.apache.org/thread.html/8338a0f605bdbb3a6098bb76f666a95fc2b2f53f37fa1ecc89f1146f%40%3Cdevnull.infra.apache.org%3E(secalert@redhat.com)
https://lists.debian.org/debian-lts-announce/2018/11/msg00005.html(secalert@redhat.com)
https://security.gentoo.org/glsa/201903-03(secalert@redhat.com)
https://usn.ubuntu.com/3805-1/(secalert@redhat.com)
https://www.debian.org/security/2018/dsa-4331(secalert@redhat.com)
http://www.securitytracker.com/id/1042012(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16839(af854a3a-2127-422b-91ae-364da2661108)
https://curl.haxx.se/docs/CVE-2018-16839.html(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/curl/curl/commit/f3a24d7916b9173c69a3e0ee790102993833d6c5(af854a3a-2127-422b-91ae-364da2661108)
https://lists.apache.org/thread.html/8338a0f605bdbb3a6098bb76f666a95fc2b2f53f37fa1ecc89f1146f%40%3Cdevnull.infra.apache.org%3E(af854a3a-2127-422b-91ae-364da2661108)
https://lists.debian.org/debian-lts-announce/2018/11/msg00005.html(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/201903-03(af854a3a-2127-422b-91ae-364da2661108)
https://usn.ubuntu.com/3805-1/(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2018/dsa-4331(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.