First published: Fri Apr 24 2015(Updated: )
The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cognos Analytics | <=2.3.20 | |
IBM Cognos Analytics | <=3.0.22 | |
Haxx Curl | =7.37.0 | |
Haxx Curl | =7.37.1 | |
Haxx Curl | =7.38.0 | |
Haxx Curl | =7.39.0 | |
Haxx Curl | =7.40.0 | |
Haxx Curl | =7.41.0 | |
Haxx Libcurl | =7.37.0 | |
Haxx Libcurl | =7.37.1 | |
Haxx Libcurl | =7.38.0 | |
Haxx Libcurl | =7.39 | |
Haxx Libcurl | =7.40.0 | |
Haxx Libcurl | =7.41.0 | |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =14.10 | |
Canonical Ubuntu Linux | =15.04 | |
Debian Debian Linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.