← All CVEs

CVE-2018-1000120

critical · 9.8

A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or worse.

9.8
CVSS
11.6%
EPSS (exploit prob.)
96th
EPSS percentile
2018-03-14
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-787

Affected products

VendorProductAffected versions
debiandebian_linux7.0
debiandebian_linux8.0
debiandebian_linux9.0
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux16.04
canonicalubuntu_linux17.10
haxxcurl>= 7.12.3, <= 7.58.0
redhatenterprise_linux_desktop7.0
redhatenterprise_linux_server7.0
redhatenterprise_linux_workstation7.0
oraclecommunications_webrtc_session_controller< 7.2
oracleenterprise_manager_ops_center12.2.2
oracleenterprise_manager_ops_center12.3.3
oraclepeoplesoft_enterprise_peopletools8.55
oraclepeoplesoft_enterprise_peopletools8.56
oraclepeoplesoft_enterprise_peopletools8.57

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-1000120