HIGH · 7.5

CVE-2012-0036

curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows remote attackers to conduct data-injection attacks via a crafte...

Vulnerability Description

curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows remote attackers to conduct data-injection attacks via a crafted URL, as demonstrated by a CRLF injection attack on the (1) IMAP, (2) POP3, or (3) SMTP protocol.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
CurlCurl7.20.0
CurlLibcurl7.20.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-0036?

CVE-2012-0036 is a vulnerability with a CVSS score of 7.5 (HIGH). curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows remote attackers to conduct data-injection attacks via a crafte...

How severe is CVE-2012-0036?

CVE-2012-0036 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-0036?

Check the references section above for vendor advisories and patch information. Affected products include: Curl Curl, Curl Libcurl.