4.3
CVSSv2

CVE-2014-3707

Published: 15/11/2014 Updated: 30/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 385
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The curl_easy_duphandle function in libcurl 7.17.1 up to and including 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to read sensitive memory information.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 14.10

canonical ubuntu linux 14.04

canonical ubuntu linux 12.04

canonical ubuntu linux 10.04

apple mac os x 10.10.4

apple mac os x 10.10.2

apple mac os x 10.10.3

apple mac os x 10.10.0

apple mac os x 10.10.1

opensuse opensuse 13.2

opensuse opensuse 13.1

oracle hyperion 11.1.2.2

oracle hyperion 11.1.2.3

debian debian linux 8.0

debian debian linux 7.0

haxx libcurl 7.19.2

haxx libcurl 7.19.3

haxx libcurl 7.21.0

haxx libcurl 7.21.1

haxx libcurl 7.22.0

haxx libcurl 7.23.0

haxx libcurl 7.29.0

haxx libcurl 7.30.0

haxx libcurl 7.37.0

haxx libcurl 7.37.1

haxx libcurl 7.17.1

haxx libcurl 7.19.4

haxx libcurl 7.19.5

haxx libcurl 7.21.2

haxx libcurl 7.21.3

haxx libcurl 7.23.1

haxx libcurl 7.24.0

haxx libcurl 7.31.0

haxx libcurl 7.32.0

haxx libcurl 7.38.0

haxx libcurl 7.18.2

haxx libcurl 7.19.0

haxx libcurl 7.19.1

haxx libcurl 7.20.0

haxx libcurl 7.20.1

haxx libcurl 7.21.6

haxx libcurl 7.21.7

haxx libcurl 7.28.0

haxx libcurl 7.28.1

haxx libcurl 7.35.0

haxx libcurl 7.36.0

haxx libcurl 7.18.0

haxx libcurl 7.18.1

haxx libcurl 7.19.6

haxx libcurl 7.19.7

haxx libcurl 7.21.4

haxx libcurl 7.21.5

haxx libcurl 7.25.0

haxx libcurl 7.26.0

haxx libcurl 7.27.0

haxx libcurl 7.33.0

haxx libcurl 7.34.0

Vendor Advisories

Synopsis Moderate: curl security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic Updated curl packages that fix multiple security issues, several bugs, andadd two enhancements are now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as ...
curl could expose sensitive information over the network ...
The curl_easy_duphandle function in libcurl 7171 through 7380, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to read sensitive memory information (CVE-2014-3707) CRLF injection vulnerability in libcurl 60 throug ...
A flaw was found in the way the libcurl library performed the duplication of connection handles If an application set the CURLOPT_COPYPOSTFIELDS option for a handle, using the handle's duplicate could cause the application to crash or disclose a portion of its memory ...

ICS Advisories

Hitachi Energy MSM Product
Critical Infrastructure Sectors: Energy