← All CVEs

CVE-2013-0249

high · 7.5

Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when negotiating SASL DIGEST-MD5 authentication, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the realm parameter in a (1) POP3, (2) SMTP or (3) IMAP message.

7.5
CVSS
21.6%
EPSS (exploit prob.)
98th
EPSS percentile
2013-03-08
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
haxxcurl7.26.0
haxxcurl7.27.0
haxxcurl7.28.0
haxxcurl7.28.1
haxxlibcurl7.26.0
haxxlibcurl7.27.0
haxxlibcurl7.28.0
haxxlibcurl7.28.1
canonicalubuntu_linux12.10

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-0249