7.5
CVSSv2

CVE-2012-0036

Published: 13/04/2012 Updated: 10/01/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

curl and libcurl 7.2x prior to 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows remote malicious users to conduct data-injection attacks via a crafted URL, as demonstrated by a CRLF injection attack on the (1) IMAP, (2) POP3, or (3) SMTP protocol.

Vulnerable Product Search on Vulmon Subscribe to Product

curl curl 7.21.1

curl curl 7.21.2

curl curl 7.23.0

curl curl 7.23.1

curl curl 7.20.1

curl curl 7.21.0

curl curl 7.21.7

curl curl 7.22.0

curl curl 7.21.3

curl curl 7.21.4

curl curl 7.20.0

curl curl 7.21.5

curl curl 7.21.6

curl libcurl 7.21.3

curl libcurl 7.21.4

curl libcurl 7.21.1

curl libcurl 7.21.2

curl libcurl 7.23.1

curl libcurl 7.20.0

curl libcurl 7.21.5

curl libcurl 7.21.6

curl libcurl 7.21.7

curl libcurl 7.20.1

curl libcurl 7.21.0

curl libcurl 7.22.0

curl libcurl 7.23.0

Vendor Advisories

curl could be tricked into injecting arbitrary data if it handled a malicious URL ...
Several vulnerabilities have been discovered in cURL, an URL transfer library The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2011-3389 This update enables OpenSSL workarounds against the BEAST attack Additional information can be found in the cURL advisory CVE-2012-0036 Dan Fandrich discovere ...