First published: Wed Jul 24 2024(Updated: )
cURL libcurl is vulnerable to a denial of service, caused by a memory allocation flaw in the utf8asn1str() function in the ASN1 parser. By using a specially crafted TLS certificate, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Credit: 2499f714-1537-4658-8207-48ae4bb9eae9
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 11 | =21H2 | |
Microsoft Windows Server 2022 | ||
Microsoft Windows 10 | =21H2 | |
Microsoft Windows Server 2019 | ||
Microsoft Windows 10 | =22H2 | |
Microsoft Windows Server 2019 | ||
Microsoft Windows Server 2022 | ||
Microsoft Windows 10 | =1809 | |
Microsoft Windows 11 | =24H2 | |
Microsoft Windows 10 | =21H2 | |
Microsoft Windows 11 | =23H2 | |
Microsoft Windows 11 | =22H2 | |
Microsoft Windows 11 | =22H2 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =22H2 | |
Microsoft Windows 10 | =21H2 | |
Microsoft Windows 11 | =23H2 | |
Microsoft Windows 11 | =21H2 | |
Microsoft Windows 11 | =24H2 | |
Microsoft Windows 10 | =22H2 | |
Microsoft CBL-Mariner | ||
Microsoft CBL-Mariner | ||
Microsoft Windows Server 2022 23H2 | ||
libcurl | >=8.6.0<8.9.0 | |
IBM Spectrum Protect | <=8.1.0.0 - 8.1.23.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6197 has a severity rating that classifies it as a denial of service vulnerability.
To fix CVE-2024-6197, apply the relevant patches or updates provided by your operating system vendor or software provider.
CVE-2024-6197 affects various versions of Microsoft Windows, Windows Server, cURL, and IBM Storage Protect Backup-Archive Client.
Yes, CVE-2024-6197 can be exploited remotely if a specially crafted TLS certificate is used by an attacker.
The impact of CVE-2024-6197 includes the potential for a denial of service, rendering affected systems unavailable.