Multiple stack-based buffer overflows in libcURL and cURL 7.12.1, and possibly other versions, allow remote malicious web servers to execute arbitrary code via base64 encoded replies that exceed the intended buffer lengths when decoded, which is not properly handled by (1) the Curl_input_ntlm function in http_ntlm.c during NTLM authentication or (2) the Curl_krb_kauth and krb4_auth functions in krb4.c during Kerberos authentication.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade curl | Jul 30, 2024 | May 2, 2005 |
| F5 Big Ip | — | — | Feb 16, 2017 | May 2, 2005 |
| Freebsd | — | Upgrade curl | Dec 10, 2025 | Feb 27, 2005 |
| Gentoo Linux | — | Upgrade net-misc/curl. | Oct 30, 2017 | May 2, 2005 |
| Ubuntu | — | Upgrade libcurl2-gssapi | Nov 8, 2024 | May 2, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub