Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-7264

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.02
EPSS Ranking 82.8%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2024-7264
  • Haxx » Libcurl » Version: 7.32.0
    cpe:2.3:a:haxx:libcurl:7.32.0
  • Haxx » Libcurl » Version: 7.33.0
    cpe:2.3:a:haxx:libcurl:7.33.0
  • Haxx » Libcurl » Version: 7.34.0
    cpe:2.3:a:haxx:libcurl:7.34.0
  • Haxx » Libcurl » Version: 7.35.0
    cpe:2.3:a:haxx:libcurl:7.35.0
  • Haxx » Libcurl » Version: 7.36.0
    cpe:2.3:a:haxx:libcurl:7.36.0
  • Haxx » Libcurl » Version: 7.37.0
    cpe:2.3:a:haxx:libcurl:7.37.0
  • Haxx » Libcurl » Version: 7.37.1
    cpe:2.3:a:haxx:libcurl:7.37.1
  • Haxx » Libcurl » Version: 7.38.0
    cpe:2.3:a:haxx:libcurl:7.38.0
  • Haxx » Libcurl » Version: 7.39
    cpe:2.3:a:haxx:libcurl:7.39
  • Haxx » Libcurl » Version: 7.39.0
    cpe:2.3:a:haxx:libcurl:7.39.0
  • Haxx » Libcurl » Version: 7.40.0
    cpe:2.3:a:haxx:libcurl:7.40.0
  • Haxx » Libcurl » Version: 7.41.0
    cpe:2.3:a:haxx:libcurl:7.41.0
  • Haxx » Libcurl » Version: 7.42
    cpe:2.3:a:haxx:libcurl:7.42
  • Haxx » Libcurl » Version: 7.42.0
    cpe:2.3:a:haxx:libcurl:7.42.0
  • Haxx » Libcurl » Version: 7.42.1
    cpe:2.3:a:haxx:libcurl:7.42.1
  • Haxx » Libcurl » Version: 7.43.0
    cpe:2.3:a:haxx:libcurl:7.43.0
  • Haxx » Libcurl » Version: 7.44.0
    cpe:2.3:a:haxx:libcurl:7.44.0
  • Haxx » Libcurl » Version: 7.45.0
    cpe:2.3:a:haxx:libcurl:7.45.0
  • Haxx » Libcurl » Version: 7.46.0
    cpe:2.3:a:haxx:libcurl:7.46.0
  • Haxx » Libcurl » Version: 7.47.0
    cpe:2.3:a:haxx:libcurl:7.47.0
  • Haxx » Libcurl » Version: 7.47.1
    cpe:2.3:a:haxx:libcurl:7.47.1
  • Haxx » Libcurl » Version: 7.48.0
    cpe:2.3:a:haxx:libcurl:7.48.0
  • Haxx » Libcurl » Version: 7.49.0
    cpe:2.3:a:haxx:libcurl:7.49.0
  • Haxx » Libcurl » Version: 7.49.1
    cpe:2.3:a:haxx:libcurl:7.49.1
  • Haxx » Libcurl » Version: 7.50.0
    cpe:2.3:a:haxx:libcurl:7.50.0
  • Haxx » Libcurl » Version: 7.50.1
    cpe:2.3:a:haxx:libcurl:7.50.1
  • Haxx » Libcurl » Version: 7.50.2
    cpe:2.3:a:haxx:libcurl:7.50.2
  • Haxx » Libcurl » Version: 7.50.3
    cpe:2.3:a:haxx:libcurl:7.50.3
  • Haxx » Libcurl » Version: 7.51.0
    cpe:2.3:a:haxx:libcurl:7.51.0
  • Haxx » Libcurl » Version: 7.52.0
    cpe:2.3:a:haxx:libcurl:7.52.0
  • Haxx » Libcurl » Version: 7.52.1
    cpe:2.3:a:haxx:libcurl:7.52.1
  • Haxx » Libcurl » Version: 7.53.0
    cpe:2.3:a:haxx:libcurl:7.53.0
  • Haxx » Libcurl » Version: 7.53.1
    cpe:2.3:a:haxx:libcurl:7.53.1
  • Haxx » Libcurl » Version: 7.54.0
    cpe:2.3:a:haxx:libcurl:7.54.0
  • Haxx » Libcurl » Version: 7.54.1
    cpe:2.3:a:haxx:libcurl:7.54.1
  • Haxx » Libcurl » Version: 7.55.0
    cpe:2.3:a:haxx:libcurl:7.55.0
  • Haxx » Libcurl » Version: 7.55.1
    cpe:2.3:a:haxx:libcurl:7.55.1
  • Haxx » Libcurl » Version: 7.56.0
    cpe:2.3:a:haxx:libcurl:7.56.0
  • Haxx » Libcurl » Version: 7.56.1
    cpe:2.3:a:haxx:libcurl:7.56.1
  • Haxx » Libcurl » Version: 7.57.0
    cpe:2.3:a:haxx:libcurl:7.57.0
  • Haxx » Libcurl » Version: 7.58.0
    cpe:2.3:a:haxx:libcurl:7.58.0
  • Haxx » Libcurl » Version: 7.59.0
    cpe:2.3:a:haxx:libcurl:7.59.0
  • Haxx » Libcurl » Version: 7.60.0
    cpe:2.3:a:haxx:libcurl:7.60.0
  • Haxx » Libcurl » Version: 7.61.0
    cpe:2.3:a:haxx:libcurl:7.61.0
  • Haxx » Libcurl » Version: 7.61.1
    cpe:2.3:a:haxx:libcurl:7.61.1
  • Haxx » Libcurl » Version: 7.62.0
    cpe:2.3:a:haxx:libcurl:7.62.0
  • Haxx » Libcurl » Version: 7.63.0
    cpe:2.3:a:haxx:libcurl:7.63.0
  • Haxx » Libcurl » Version: 7.64.0
    cpe:2.3:a:haxx:libcurl:7.64.0
  • Haxx » Libcurl » Version: 7.64.1
    cpe:2.3:a:haxx:libcurl:7.64.1
  • Haxx » Libcurl » Version: 7.65.0
    cpe:2.3:a:haxx:libcurl:7.65.0
  • Haxx » Libcurl » Version: 7.65.1
    cpe:2.3:a:haxx:libcurl:7.65.1
  • Haxx » Libcurl » Version: 7.65.2
    cpe:2.3:a:haxx:libcurl:7.65.2
  • Haxx » Libcurl » Version: 7.65.3
    cpe:2.3:a:haxx:libcurl:7.65.3
  • Haxx » Libcurl » Version: 7.66.0
    cpe:2.3:a:haxx:libcurl:7.66.0
  • Haxx » Libcurl » Version: 7.67.0
    cpe:2.3:a:haxx:libcurl:7.67.0
  • Haxx » Libcurl » Version: 7.68.0
    cpe:2.3:a:haxx:libcurl:7.68.0
  • Haxx » Libcurl » Version: 7.69.0
    cpe:2.3:a:haxx:libcurl:7.69.0
  • Haxx » Libcurl » Version: 7.69.1
    cpe:2.3:a:haxx:libcurl:7.69.1
  • Haxx » Libcurl » Version: 7.70.0
    cpe:2.3:a:haxx:libcurl:7.70.0
  • Haxx » Libcurl » Version: 7.71.0
    cpe:2.3:a:haxx:libcurl:7.71.0
  • Haxx » Libcurl » Version: 7.71.1
    cpe:2.3:a:haxx:libcurl:7.71.1
  • Haxx » Libcurl » Version: 7.72.0
    cpe:2.3:a:haxx:libcurl:7.72.0
  • Haxx » Libcurl » Version: 7.73.0
    cpe:2.3:a:haxx:libcurl:7.73.0
  • Haxx » Libcurl » Version: 7.74.0
    cpe:2.3:a:haxx:libcurl:7.74.0
  • Haxx » Libcurl » Version: 7.75.0
    cpe:2.3:a:haxx:libcurl:7.75.0
  • Haxx » Libcurl » Version: 7.77.0
    cpe:2.3:a:haxx:libcurl:7.77.0
  • Haxx » Libcurl » Version: 7.78.0
    cpe:2.3:a:haxx:libcurl:7.78.0
  • Haxx » Libcurl » Version: 7.79.0
    cpe:2.3:a:haxx:libcurl:7.79.0
  • Haxx » Libcurl » Version: 7.79.1
    cpe:2.3:a:haxx:libcurl:7.79.1
  • Haxx » Libcurl » Version: 7.80.0
    cpe:2.3:a:haxx:libcurl:7.80.0
  • Haxx » Libcurl » Version: 7.81.0
    cpe:2.3:a:haxx:libcurl:7.81.0
  • Haxx » Libcurl » Version: 7.82.0
    cpe:2.3:a:haxx:libcurl:7.82.0
  • Haxx » Libcurl » Version: 7.83.0
    cpe:2.3:a:haxx:libcurl:7.83.0
  • Haxx » Libcurl » Version: 7.83.1
    cpe:2.3:a:haxx:libcurl:7.83.1
  • Haxx » Libcurl » Version: 7.84.0
    cpe:2.3:a:haxx:libcurl:7.84.0
  • Haxx » Libcurl » Version: 7.85.0
    cpe:2.3:a:haxx:libcurl:7.85.0
  • Haxx » Libcurl » Version: 7.86.0
    cpe:2.3:a:haxx:libcurl:7.86.0
  • Haxx » Libcurl » Version: 7.87.0
    cpe:2.3:a:haxx:libcurl:7.87.0
  • Haxx » Libcurl » Version: 7.88.0
    cpe:2.3:a:haxx:libcurl:7.88.0
  • Haxx » Libcurl » Version: 7.88.1
    cpe:2.3:a:haxx:libcurl:7.88.1
  • Haxx » Libcurl » Version: 8.0.0
    cpe:2.3:a:haxx:libcurl:8.0.0
  • Haxx » Libcurl » Version: 8.0.1
    cpe:2.3:a:haxx:libcurl:8.0.1
  • Haxx » Libcurl » Version: 8.1.0
    cpe:2.3:a:haxx:libcurl:8.1.0
  • Haxx » Libcurl » Version: 8.1.1
    cpe:2.3:a:haxx:libcurl:8.1.1
  • Haxx » Libcurl » Version: 8.1.2
    cpe:2.3:a:haxx:libcurl:8.1.2
  • Haxx » Libcurl » Version: 8.2.0
    cpe:2.3:a:haxx:libcurl:8.2.0
  • Haxx » Libcurl » Version: 8.2.1
    cpe:2.3:a:haxx:libcurl:8.2.1
  • Haxx » Libcurl » Version: 8.3.0
    cpe:2.3:a:haxx:libcurl:8.3.0
  • Haxx » Libcurl » Version: 8.4.0
    cpe:2.3:a:haxx:libcurl:8.4.0
  • Haxx » Libcurl » Version: 8.5.0
    cpe:2.3:a:haxx:libcurl:8.5.0
  • Haxx » Libcurl » Version: 8.6.0
    cpe:2.3:a:haxx:libcurl:8.6.0
  • Haxx » Libcurl » Version: 8.7.0
    cpe:2.3:a:haxx:libcurl:8.7.0
  • Haxx » Libcurl » Version: 8.7.1
    cpe:2.3:a:haxx:libcurl:8.7.1
  • Haxx » Libcurl » Version: 8.8.0
    cpe:2.3:a:haxx:libcurl:8.8.0
  • Haxx » Libcurl » Version: 8.9.0
    cpe:2.3:a:haxx:libcurl:8.9.0


Contact Us

Shodan ® - All rights reserved