CVE-2015-3237

cURL & libcurl <7.43 - Info Disclosure/DoS

Title source: llm
STIX 2.1

Description

The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.

References (11)

Core 11
Core References
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160660.html
Patch, Third Party Advisory x_refsource_confirm
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
Vendor Advisory x_refsource_confirm
http://curl.haxx.se/docs/adv_20150617B.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036371
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/91787
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201509-02
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/75387

Scores

EPSS 0.0513
EPSS Percentile 90.0%

Details

CWE
CWE-20
Status published
Products (14)
haxx/curl 7.40.0
haxx/curl 7.41.0
haxx/curl 7.42.0
haxx/curl 7.42.1
haxx/libcurl 7.40.0
haxx/libcurl 7.41.0
haxx/libcurl 7.42.0
haxx/libcurl 7.42.1
hp/system_management_homepage < 7.5.3.1
oracle/enterprise_manager_ops_center 12.1.4
... and 4 more
Published Jun 22, 2015
Tracked Since Feb 18, 2026