CVE-2015-3144

The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:C/I:C/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
oraclemysql_enterprise_monitor
𝑥
≤ 2.3.20
oraclemysql_enterprise_monitor
𝑥
≤ 3.0.22
haxxcurl
7.37.0
haxxcurl
7.37.1
haxxcurl
7.38.0
haxxcurl
7.39.0
haxxcurl
7.40.0
haxxcurl
7.41.0
haxxlibcurl
7.37.0
haxxlibcurl
7.37.1
haxxlibcurl
7.38.0
haxxlibcurl
7.39
haxxlibcurl
7.40.0
haxxlibcurl
7.41.0
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
canonicalubuntu_linux
14.10
canonicalubuntu_linux
15.04
debiandebian_linux
7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
curl
bullseye
7.74.0-1.3+deb11u13
fixed
wheezy
not-affected
squeeze
not-affected
bullseye (security)
7.74.0-1.3+deb11u11
fixed
bookworm
7.88.1-10+deb12u7
fixed
bookworm (security)
7.88.1-10+deb12u5
fixed
sid
8.10.1-2
fixed
trixie
8.10.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
curl
vivid
Fixed 7.38.0-3ubuntu2.2
released
utopic
Fixed 7.37.1-1ubuntu3.4
released
trusty
not-affected
precise
not-affected
lucid
not-affected
References