CVE-2013-2174: Buffer Overflow
Heap-based buffer overflow in the curleasyunescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string ending in a "%" (percent) character.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2174?
CVE-2013-2174 is rated as critical due to its potential for remote code execution and denial of service.
How do I fix CVE-2013-2174?
To fix CVE-2013-2174, upgrade to a version of cURL or libcurl that is 7.31.0 or later.
What devices are affected by CVE-2013-2174?
CVE-2013-2174 affects cURL and libcurl versions 7.7 through 7.30.0 across various operating systems.
What kind of attack is CVE-2013-2174 associated with?
CVE-2013-2174 is associated with heap-based buffer overflow attacks that can lead to application crashes or arbitrary code execution.
Is my system vulnerable to CVE-2013-2174?
If your system is running any version of cURL or libcurl from 7.7 to 7.30.0, it is vulnerable to CVE-2013-2174.