Lucene search

K
f5F5F5:K10196624
HistoryApr 21, 2017 - 12:00 a.m.

K10196624 : libcurl vulnerability CVE-2016-8618

2017-04-2100:00:00
my.f5.com
14

7.8 High

AI Score

Confidence

High

0.013 Low

EPSS

Percentile

86.0%

Security Advisory Description

The libcurl API function called curl_maprintf() before version 7.51.0 can be tricked into doing a double-free due to an unsafe size_t multiplication, on systems using 32 bit size_t variables. (CVE-2016-8618)

Impact

A custom monitor or script that calls the curl command may allow unauthorized disclosure of information, unauthorized modification, and disruption of service. Thebig3d process, which includes thelibcurl library, may allow unauthorized disclosure of information, unauthorized modification, and disruption of service.