A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related to closing an easy handle. When closing and cleaning up an 'easy' handle in the `Curl_close()` function, the library code first frees a struct (without nulling the pointer) and might then subsequently erroneously write to a struct field within that already freed struct.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 4.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade curl | Nov 9, 2018 | Oct 31, 2018 |
| Amazon Linux Ami 2 | — | Upgrade libcurlUpgrade curl-debuginfoUpgrade libcurl-develUpgrade curl | Apr 27, 2020 | Oct 31, 2018 |
| Amazon_linux | — | Upgrade curl | Jan 25, 2019 | Oct 31, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Oct 31, 2018 |
| Debian | — | Upgrade curl | Jul 30, 2024 | Oct 31, 2018 |
| Freebsd | — | Upgrade curl | Nov 2, 2018 | Nov 1, 2018 |
| Gentoo Linux | — | Upgrade net-misc/curl. | Mar 11, 2019 | Oct 31, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libcurlUpgrade libcurl-develUpgrade curl | Jun 17, 2020 | Oct 31, 2018 |
| Oracle Solaris | — | Upgrade web/curl to version 7.62.0-11.4.4.0.1.3.0 on Solaris 11.4 | Dec 17, 2018 | Oct 31, 2018 |
| Suse | — | Upgrade libcurl4-openssl1-32bitUpgrade libcurl4-miniUpgrade curl-miniUpgrade libcurl4-openssl1Upgrade libcurl-devel-32bitUpgrade libcurl-develUpgrade curl-openssl1Upgrade curlUpgrade libcurl4-x86Upgrade libcurl4Upgrade libcurl-mini-develUpgrade libcurl4-openssl1-x86Upgrade libcurl4-32bit | Nov 3, 2018 | Oct 31, 2018 |
| Ubuntu | — | Upgrade libcurl3Upgrade libcurl3-gnutlsUpgrade libcurl4Upgrade libcurl3-nssUpgrade curl | Nov 9, 2018 | Oct 31, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 31, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub