Vulnerability identifier: #VU64682
Vulnerability risk: Medium
Exploitation vector: Network
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insecure processing of compressed HTTP responses. A malicious server can send a specially crafted HTTP response to curl and perform a denial of service attack by forcing curl to spend enormous amounts of allocated heap memory, or trying to and returning out of memory errors.
Install updates from vendor's website.
Vulnerable software versions
cURL: 7.57.0 - 7.83.1
Fixed software versions
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?