CVE-2018-1000300: Buffer Overflow
curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122: Heap-based Buffer Overflow vulnerability in denial of service and more that can result in curl might overflow a heap based memory buffer when closing down an FTP connection with very long server command replies.. This vulnerability appears to have been fixed in curl < 7.54.1 and curl >= 7.60.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/curlto a version that resolves this vulnerability.Fixed in 7.74.0-1.3+deb11u13Fixed in 7.74.0-1.3+deb11u16Fixed in 7.88.1-10+deb12u14Fixed in 7.88.1-10+deb12u5Fixed in 8.14.1-2+deb13u3Fixed in 8.20.0-5Fixed in 8.21.0~rc2-1 - Upgrade
Upgrade
debian/curlto a version that resolves this vulnerability.Fixed in 7.74.0-1.3+deb11u13 - Upgrade
Upgrade
debian/curlto a version that resolves this vulnerability.Fixed in 7.74.0-1.3+deb11u16 - Upgrade
Upgrade
debian/curlto a version that resolves this vulnerability.Fixed in 7.88.1-10+deb12u14 - Upgrade
Upgrade
debian/curlto a version that resolves this vulnerability.Fixed in 7.88.1-10+deb12u5 - Upgrade
Upgrade
debian/curlto a version that resolves this vulnerability.Fixed in 8.14.1-2+deb13u3 - Upgrade
Upgrade
debian/curlto a version that resolves this vulnerability.Fixed in 8.20.0-5 - Upgrade
Upgrade
debian/curlto a version that resolves this vulnerability.Fixed in 8.21.0~rc2-1 - Upgrade
Upgrade
curlto a version that resolves this vulnerability.Fixed in 7.60.0
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2018-1000300.
What is the severity of CVE-2018-1000300?
CVE-2018-1000300 has a severity rating of 9.8 (critical).
What is the affected software for CVE-2018-1000300?
The affected software for CVE-2018-1000300 is curl versions 7.54.1 to 7.59.0.
How can I fix CVE-2018-1000300?
To fix CVE-2018-1000300, update curl to version 7.60.0 or above.
Where can I find more information about CVE-2018-1000300?
You can find more information about CVE-2018-1000300 at the following references: [1] [2] [3].