CVE-2014-3707: Infoleak
The curleasyduphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPTCOPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to read sensitive memory information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3707?
CVE-2014-3707 has been identified as a medium severity vulnerability due to its potential to expose sensitive memory information.
How do I fix CVE-2014-3707?
To fix CVE-2014-3707, users should upgrade to a version of libcurl newer than 7.38.0, where the vulnerability has been addressed.
Which versions are affected by CVE-2014-3707?
CVE-2014-3707 affects libcurl versions from 7.17.1 to 7.38.0.
What type of vulnerability is CVE-2014-3707?
CVE-2014-3707 is an out-of-bounds read vulnerability that may allow remote web servers to access sensitive memory data.
What systems are impacted by CVE-2014-3707?
CVE-2014-3707 impacts various systems including Ubuntu Linux, macOS Yosemite, openSUSE, and Oracle Hyperion running the affected versions of libcurl.