CVE-2015-3145: Buffer Overflow
The sanitizecookiepath function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly have other unspecified impact via a cookie path containing only a double-quote character.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3145?
CVE-2015-3145 is considered medium severity due to its potential to cause denial of service through out-of-bounds writes.
How do I fix CVE-2015-3145?
To mitigate CVE-2015-3145, update cURL or libcurl to version 7.42.0 or higher.
What versions of cURL are affected by CVE-2015-3145?
CVE-2015-3145 affects cURL and libcurl versions from 7.31.0 to 7.41.0.
What types of attacks are possible due to CVE-2015-3145?
CVEs 2015-3145 may allow attackers to conduct denial of service attacks by causing crashes through specific cookie paths.
Which platforms are impacted by CVE-2015-3145?
CVE-2015-3145 affects various platforms including Fedora, Ubuntu, Debian, macOS, and Oracle Solaris.