PT-2018-1976 · Curl+3 · Curl+3

Harry Sintonen

·

Published

2018-09-28

·

Updated

2026-05-18

·

CVE-2018-16839

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Curl versions 7.33.0 through 7.61.1
Description The issue is related to a buffer overrun in the SASL authentication code, which may lead to denial of service. This buffer overrun is located in the Curl auth create plain message function and occurs in the heap. Exploitation of this issue may allow a remote attacker to cause a denial of service.
Recommendations For Curl versions 7.33.0 through 7.61.1, update to a version that contains a fix for this issue to prevent potential denial of service attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Heap Based Buffer Overflow

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2581
BDU:2018-01586
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2018-16839
DLA-1568-1
DSA-4331-1
OPENSUSE-SU-2018_3706-1
OPENSUSE-SU-2024:10582-1
SUSE-SU-2018:3624-1
SUSE-SU-2018_3624-1
SUSE-SU-2019:0339-1
SUSE-SU-2019:0996-1
SUSE-SU-2019_0996-1
USN-3805-1

Affected Products

Alt Linux
Curl
Suse
Ubuntu