Back

HIGH

curl: printf floating point buffer overflow

Published Apr 23, 2018

Description

curl before version 7.52.0 is vulnerable to a buffer overflow when doing a large floating point output in libcurl's implementation of the printf() functions. If there are any application that accepts a format string from the outside without necessary input filtering, it could allow remote attacks.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 23, 2018
Updated Apr 15, 2026
Reserved Nov 23, 2016
CISA Vulnrichment
Updated Apr 15, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Dec 21, 2016