
We found results for “”
CVE-2016-8617
Good to know:

Date: July 31, 2018
The base64 encode function in curl before version 7.51.0 is prone to a buffer being under allocated in 32bit systems if it receives at least 1Gb as input via `CURLOPT_USERNAME`.
Language: C
Severity Score
Related Resources (17)
Severity Score
Top Fix

Upgrade Version
Upgrade to version cmake-native - 3.15.5;cmake-native - 3.7.0;syntax/chat - no_fix;curl - 7.51.0-1;lib32-libcurl-compat - 7.51.0-1;cmake - 3.15.5;cmake - 3.7.0;lib32-libcurl-gnutls - 7.51.0-1;libcurl-gnutls - 7.51.0-1;lib32-curl - 7.51.0-1;libcurl-compat - 7.51.0-1;curl - 7.51.0
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | LOCAL |
Attack Complexity (AC): | HIGH |
Privileges Required (PR): | LOW |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | HIGH |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | LOCAL |
Access Complexity (AC): | MEDIUM |
Authentication (AU): | NONE |
Confidentiality (C): | PARTIAL |
Integrity (I): | PARTIAL |
Availability (A): | PARTIAL |
Additional information: |