← All CVEs

CVE-2012-0036

high · 7.5

curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows remote attackers to conduct data-injection attacks via a crafted URL, as demonstrated by a CRLF injection attack on the (1) IMAP, (2) POP3, or (3) SMTP protocol.

7.5
CVSS
16.1%
EPSS (exploit prob.)
97th
EPSS percentile
2012-04-13
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-89

Affected products

VendorProductAffected versions
curlcurl7.20.0
curlcurl7.20.1
curlcurl7.21.0
curlcurl7.21.1
curlcurl7.21.2
curlcurl7.21.3
curlcurl7.21.4
curlcurl7.21.5
curlcurl7.21.6
curlcurl7.21.7
curlcurl7.22.0
curlcurl7.23.0
curlcurl7.23.1
curllibcurl7.20.0
curllibcurl7.20.1
curllibcurl7.21.0
curllibcurl7.21.1
curllibcurl7.21.2
curllibcurl7.21.3
curllibcurl7.21.4
curllibcurl7.21.5
curllibcurl7.21.6
curllibcurl7.21.7
curllibcurl7.22.0
curllibcurl7.23.0
curllibcurl7.23.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2012-0036