CVE-2015-3144: Buffer Overflow
The fixhostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3144?
CVE-2015-3144 has a CVSS score that indicates it is a medium severity vulnerability due to potential denial of service conditions.
How do I fix CVE-2015-3144?
To remediate CVE-2015-3144, update cURL to version 7.41.1 or later.
What systems are affected by CVE-2015-3144?
CVE-2015-3144 affects cURL and libcurl versions 7.37.0 to 7.41.0 as well as associated applications utilizing these libraries.
What type of vulnerability is CVE-2015-3144?
CVE-2015-3144 is classified as a denial of service vulnerability that may lead to out-of-bounds read or write issues.
Can CVE-2015-3144 lead to data breaches?
While CVE-2015-3144 primarily leads to denial of service, its exploitation could potentially allow further unspecified impacts depending on the environment.