Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-1000005

libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers. It was reported (https://github.com/curl/curl/pull/2231) that reading an HTTP/2 trailer could mess up future trailers since the stored size was one byte less than required. The problem is that the code that creates HTTP/1-like headers from the HTTP/2 trailer data once appended a string like `:` to the target buffer, while this was recently changed to `: ` (a space was added after the colon) but the following math wasn't updated correspondingly. When accessed, the data is read out of bounds and causes either a crash or that the (too large) data gets passed to client write. This could lead to a denial-of-service situation or an information disclosure if someone has a service that echoes back or uses the trailers for something.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.2%
CVSS Severity
CVSS v3 Score 9.1
CVSS v2 Score 6.4
Products affected by CVE-2018-1000005
  • Haxx » Libcurl » Version: 7.49.0
    cpe:2.3:a:haxx:libcurl:7.49.0
  • Haxx » Libcurl » Version: 7.49.1
    cpe:2.3:a:haxx:libcurl:7.49.1
  • Haxx » Libcurl » Version: 7.50.0
    cpe:2.3:a:haxx:libcurl:7.50.0
  • Haxx » Libcurl » Version: 7.50.1
    cpe:2.3:a:haxx:libcurl:7.50.1
  • Haxx » Libcurl » Version: 7.50.2
    cpe:2.3:a:haxx:libcurl:7.50.2
  • Haxx » Libcurl » Version: 7.50.3
    cpe:2.3:a:haxx:libcurl:7.50.3
  • Haxx » Libcurl » Version: 7.51.0
    cpe:2.3:a:haxx:libcurl:7.51.0
  • Haxx » Libcurl » Version: 7.52.0
    cpe:2.3:a:haxx:libcurl:7.52.0
  • Haxx » Libcurl » Version: 7.52.1
    cpe:2.3:a:haxx:libcurl:7.52.1
  • Haxx » Libcurl » Version: 7.53.0
    cpe:2.3:a:haxx:libcurl:7.53.0
  • Haxx » Libcurl » Version: 7.53.1
    cpe:2.3:a:haxx:libcurl:7.53.1
  • Haxx » Libcurl » Version: 7.54.0
    cpe:2.3:a:haxx:libcurl:7.54.0
  • Haxx » Libcurl » Version: 7.54.1
    cpe:2.3:a:haxx:libcurl:7.54.1
  • Haxx » Libcurl » Version: 7.55.0
    cpe:2.3:a:haxx:libcurl:7.55.0
  • Haxx » Libcurl » Version: 7.55.1
    cpe:2.3:a:haxx:libcurl:7.55.1
  • Haxx » Libcurl » Version: 7.56.0
    cpe:2.3:a:haxx:libcurl:7.56.0
  • Haxx » Libcurl » Version: 7.56.1
    cpe:2.3:a:haxx:libcurl:7.56.1
  • Haxx » Libcurl » Version: 7.57.0
    cpe:2.3:a:haxx:libcurl:7.57.0
  • Canonical » Ubuntu Linux » Version: 14.04
    cpe:2.3:o:canonical:ubuntu_linux:14.04
  • Canonical » Ubuntu Linux » Version: 16.04
    cpe:2.3:o:canonical:ubuntu_linux:16.04
  • Canonical » Ubuntu Linux » Version: 17.10
    cpe:2.3:o:canonical:ubuntu_linux:17.10
  • Debian » Debian Linux » Version: 8.0
    cpe:2.3:o:debian:debian_linux:8.0
  • Debian » Debian Linux » Version: 9.0
    cpe:2.3:o:debian:debian_linux:9.0


Contact Us

Shodan ® - All rights reserved