HIGH · 9.0

CVE-2015-3144

The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and cr...

Vulnerability Description

The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."

CVSS Score

9.0

HIGH

AV:N/AC:L/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
OracleMysql Enterprise Monitor<= 2.3.20
HaxxCurl7.37.0
HaxxLibcurl7.37.0
CanonicalUbuntu Linux12.04
DebianDebian Linux7.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-3144?

CVE-2015-3144 is a vulnerability with a CVSS score of 9.0 (HIGH). The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and cr...

How severe is CVE-2015-3144?

CVE-2015-3144 has been rated HIGH with a CVSS base score of 9.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-3144?

Check the references section above for vendor advisories and patch information. Affected products include: Oracle Mysql Enterprise Monitor, Haxx Curl, Haxx Libcurl, Canonical Ubuntu Linux, Debian Debian Linux.