6.4
CVSSv2

CVE-2015-3237

Published: 22/06/2015 Updated: 17/10/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

The smb_request_state function in cURL and libcurl 7.40.0 up to and including 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

haxx libcurl 7.40.0

haxx libcurl 7.41.0

haxx curl 7.40.0

haxx curl 7.41.0

haxx curl 7.42.0

haxx curl 7.42.1

haxx libcurl 7.42.0

haxx libcurl 7.42.1

hp system management homepage

oracle glassfish server 3.1.2

oracle enterprise manager ops center 12.1.4

oracle enterprise manager ops center 12.2.2

oracle enterprise manager ops center 12.3.2

oracle glassfish server 3.0.1

Vendor Advisories

As <a href="curlhaxxse/docs/adv_20150617Ahtml">discussed upstream</a>, libcurl can wrongly send HTTP credentials when re-using connections (CVE-2015-3236) Also <a href="curlhaxxse/docs/adv_20150617Bhtml">discussed upstream</a>, libcurl can get tricked by a malicious SMB server to send off data it did not ...
The smb_request_state function in cURL and libcurl 7400 through 7421 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values ...