The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade curl | Aug 30, 2017 | Apr 15, 2014 |
| Centos_linux | — | Upgrade curlUpgrade libcurlUpgrade libcurl-devel | Dec 1, 2016 | Apr 15, 2014 |
| Debian | — | Upgrade curl | Jul 30, 2024 | Apr 15, 2014 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Nov 25, 2014 |
| Gentoo Linux | — | Upgrade net-misc/curl. | Oct 30, 2017 | Apr 15, 2014 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 13, 2015 | Apr 15, 2014 |
| Oracle_linux | — | Upgrade libcurlUpgrade libcurl-develUpgrade curl | Oct 16, 2024 | Apr 15, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 26, 2014 |
| Suse | — | Upgrade openldap2-devel-32bitUpgrade cyrus-sasl-openssl1-digestmd5Upgrade libcurl4-openssl1-32bitUpgrade libldap-openssl1-2_4-2-32bitUpgrade compat-libldap-2_3-0Upgrade libldap-2_4-2Upgrade openldap2-back-perlUpgrade cyrus-sasl-openssl1-32bitUpgrade cyrus-sasl-openssl1-x86Upgrade libldap-2_4-2-x86Upgrade curlUpgrade openldap2Upgrade libcurl-develUpgrade cyrus-sasl-openssl1-crammd5Upgrade libcurl4-openssl1-x86Upgrade openldap2-back-metaUpgrade openldap2-clientUpgrade cyrus-sasl-openssl1-gssapiUpgrade libcurl4-x86Upgrade curl-openssl1Upgrade cyrus-sasl-openssl1-ntlmUpgrade libldap-2_4-2-32bitUpgrade libcurl4Upgrade libcurl4-32bitUpgrade libldap-openssl1-2_4-2Upgrade openldap2-develUpgrade cyrus-sasl-openssl1-otpUpgrade cyrus-sasl-openssl1Upgrade cyrus-sasl-openssl1-plainUpgrade libldap-openssl1-2_4-2-x86Upgrade libcurl4-openssl1 | Dec 18, 2015 | Apr 15, 2014 |
| Ubuntu | — | Upgrade libcurl3Upgrade libcurl3-nssUpgrade libcurl3-gnutls | Nov 8, 2024 | Apr 15, 2014 |
| Vmsa 2014 0012 | — | Upgrade VMware ESXi 5.5 to build number 2068190Upgrade VMware ESXi 5.1 to build number 2323236 | Oct 28, 2015 | Apr 15, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub