Back

MEDIUM

curl: zlib-compression causes curl to pass more than CURL_MAX_WRITE_SIZE bytes to write callback

Published Mar 19, 2010

Description

content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that requests automatic decompression, which might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact by sending crafted compressed data to an application that relies on the intended data-length limit.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (38)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 19, 2010
Updated Aug 7, 2024
Reserved Feb 26, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Feb 9, 2010