curl / Docs / Vulnerability table / 7.1 vulnerabilities

Vulnerabilities in curl 7.1

curl version 7.1 was released on August 7 2000. The following 17 security problems are known to exist in this version.

FlawFrom versionTo and includingCVECWE
Auth/cookie leak on redirect4.97.82.0CVE-2022-27776CWE-522: Insufficiently Protected Credentials
Credential leak on redirect4.97.82.0CVE-2022-27774CWE-522: Insufficiently Protected Credentials
trusting FTP PASV responses4.07.73.0CVE-2020-8284CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
HTTP authentication leak in redirects6.07.57.0CVE-2018-1000007CWE-522: Insufficiently Protected Credentials
--write-out out of buffer read6.57.53.1CVE-2017-7407CWE-126: Buffer Over-read
printf floating point buffer overflow5.47.51.0CVE-2016-9586CWE-121: Stack-based Buffer Overflow
cookie injection for other servers4.97.50.3CVE-2016-8615CWE-187: Partial Comparison
double-free in curl_maprintf5.47.50.3CVE-2016-8618CWE-415: Double Free
invalid URL parsing with '#'6.07.50.3CVE-2016-8624CWE-172: Encoding Error
TLS session resumption client cert bypass5.07.50.0CVE-2016-5419CWE-305: Authentication Bypass by Primary Weakness
sensitive HTTP server headers also sent to proxies4.07.42.0CVE-2015-3153CWE-201: Information Exposure Through Sent Data
URL request injection6.07.39.0CVE-2014-8150CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
cookie leak with IP address as domain4.07.37.1CVE-2014-3613CWE-201: Information Exposure Through Sent Data
cookie domain tailmatch6.07.29.0CVE-2013-1944CWE-201: Information Exposure Through Sent Data
Arbitrary File Access6.07.19.3CVE-2009-0037CWE-142: Improper Neutralization of Value Delimiters
Proxy Authentication Header Information Leakage4.57.10.6CVE-2003-1605CWE-201: Information Exposure Through Sent Data
FTP Server Response Buffer Overflow6.07.4CVE-2000-0973CWE-121: Stack-based Buffer Overflow

Changelog for curl 7.1

See vulnerability summary for the previous release: 6.5.2 or the subsequent release: 7.1.1