curl / Docs / Vulnerability table / 5.4 vulnerabilities

Vulnerabilities in curl 5.4

curl version 5.4 was released on January 7 1999. The following 13 security problems are known to exist in this version.

FlawFrom versionTo and including
control code in cookie denial of service4.97.84.0
Auth/cookie leak on redirect4.97.82.0
Credential leak on redirect4.97.82.0
trusting FTP PASV responses4.07.73.0
printf floating point buffer overflow5.47.51.0
cookie injection for other servers4.97.50.3
double free in curl_maprintf5.47.50.3
TLS session resumption client cert bypass5.07.50.0
remote file name path traversal in curl tool for Windows4.07.46.0
sensitive HTTP server headers also sent to proxies4.07.42.0
cookie leak with IP address as domain4.07.37.1
cookie domain tailmatch4.77.29.0
Proxy Authentication Header Information Leakage4.57.10.6

CVE data for 5.4 provided as JSON.

Changelog for curl 5.4

See vulnerability summary for the previous release: 5.3 or the subsequent release: 5.5