PT-2019-1514 · Curl+5 · Libcurl+5

Brian Carpenter

·

Published

2019-01-18

·

Updated

2026-05-18

·

CVE-2019-3823

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libcurl versions 7.34.0 through 7.64.0
Description The issue is related to a heap out-of-bounds read in the code handling the end-of-response for SMTP. This occurs when the buffer passed to smtp endofresp() is not null terminated and contains no character ending the parsed number, and len is set to 5. As a result, the strtol() call reads beyond the allocated buffer, but the read contents are not returned to the caller. The exploitation of this issue may allow a remote attacker to impact the confidentiality, integrity, and availability of protected information, potentially leading to a denial of service.
Recommendations For libcurl versions 7.34.0 through 7.64.0, update to a version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1185
BDU:2019-00966
BDU:2019-01668
CESA-2019_3701
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2019-3823
DLA-1672-1
DSA-4386-1
ELSA-2019-3701
OPENSUSE-SU-2019:0174-1
OPENSUSE-SU-2019_0173-1
OPENSUSE-SU-2019_0174-1
OPENSUSE-SU-2024:10582-1
RHSA-2019:3701
RHSA-2019_3701
SUSE-SU-2019:0248-1
SUSE-SU-2019:0249-1
SUSE-SU-2019:0249-2
SUSE-SU-2019:0339-1
USN-3882-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libcurl