Back

CRITICAL

curl: URL unescape heap overflow via integer truncation

Published Jul 31, 2018

Description

The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if this function would be made to allocate a unscape destination buffer larger than 2GB, it would return that new length in a signed 32 bit integer variable, thus the length would get either just truncated or both truncated and turned negative. That could then lead to libcurl writing outside of its heap based buffer.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 31, 2018
Updated Apr 15, 2026
Reserved Oct 12, 2016
CISA Vulnrichment
Updated Apr 15, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Nov 2, 2016