Heap Buffer Overflow in libcurl Affects Multiple Versions by Curl
CVE-2018-16890
Key Information:
- Vendor
The Curl Project
- Status
- Vendor
- CVE Published:
- 6 February 2019
Badges
What is CVE-2018-16890?
A vulnerability exists in libcurl versions from 7.36.0 to before 7.64.0, which can lead to a heap buffer out-of-bounds read. This issue arises due to improper validation of incoming NTLM type-2 messages in the ntlm_decode_type2_target function. If an attacker controls an NTLM server, they may exploit this vulnerability by providing a crafted length or offset value, which can result in the application reading beyond allocated memory, potentially leading to information disclosure or application instability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
curl 7.64.0
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
