The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade curl | Aug 30, 2017 | Apr 15, 2014 |
| Centos_linux | — | Upgrade libcurl-develUpgrade libcurlUpgrade curl | Dec 1, 2016 | Apr 15, 2014 |
| Debian | — | Upgrade curl | Jul 30, 2024 | Apr 15, 2014 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Nov 25, 2014 |
| Gentoo Linux | — | Upgrade net-misc/curl. | Oct 30, 2017 | Apr 15, 2014 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 13, 2015 | Apr 15, 2014 |
| Oracle_linux | — | Upgrade libcurlUpgrade libcurl-develUpgrade curl | Oct 16, 2024 | Apr 15, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 26, 2014 |
| Suse | — | Upgrade compat-libldap-2_3-0Upgrade libcurl-develUpgrade curlUpgrade cyrus-sasl-openssl1-x86Upgrade libldap-openssl1-2_4-2-32bitUpgrade libldap-2_4-2Upgrade cyrus-sasl-openssl1-32bitUpgrade openldap2-back-perlUpgrade libldap-2_4-2-x86Upgrade libcurl4-openssl1-32bitUpgrade openldap2-devel-32bitUpgrade cyrus-sasl-openssl1-digestmd5Upgrade openldap2Upgrade libcurl4Upgrade cyrus-sasl-openssl1-crammd5Upgrade openldap2-develUpgrade cyrus-sasl-openssl1-otpUpgrade openldap2-back-metaUpgrade curl-openssl1Upgrade openldap2-clientUpgrade libcurl4-openssl1-x86Upgrade cyrus-sasl-openssl1-plainUpgrade cyrus-sasl-openssl1Upgrade libldap-2_4-2-32bitUpgrade libcurl4-32bitUpgrade libcurl4-x86Upgrade cyrus-sasl-openssl1-ntlmUpgrade libcurl4-openssl1Upgrade cyrus-sasl-openssl1-gssapiUpgrade libldap-openssl1-2_4-2-x86Upgrade libldap-openssl1-2_4-2 | Dec 18, 2015 | Apr 15, 2014 |
| Ubuntu | — | Upgrade libcurl3-gnutlsUpgrade libcurl3-nssUpgrade libcurl3 | Nov 8, 2024 | Apr 15, 2014 |
| Vmsa 2014 0012 | — | Upgrade VMware ESXi 5.1 to build number 2323236Upgrade VMware ESXi 5.5 to build number 2068190 | Oct 28, 2015 | Apr 15, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub