PT-2017-10804 · Curl+1 · Libcurl+1

Even Rouault

·

Published

2017-08-09

·

Updated

2026-05-18

·

CVE-2017-1000099

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions libcurl (affected versions not specified)
Description The issue arises when libcurl is used to retrieve a file from a file:// URL, and it attempts to provide meta-data about the file using HTTP-like headers. However, the code sends the wrong buffer to the user, which could be either stdout or the application's provided callback. This wrong buffer is an uninitialized memory area allocated on the heap. If this buffer does not contain any zero byte, the code will continue to display the data following that buffer in memory, potentially leading to the inadvertent display of other private data from the heap.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2036
ALT-PU-2018-2456
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2017-1000099
MGASA-2017-0281
OPENSUSE-SU-2024:10582-1

Affected Products

Alt Linux
Libcurl