curl / Docs / Vulnerability table / 7.2.1 vulnerabilities

Vulnerabilities in curl 7.2.1

curl version 7.2.1 was released on August 31 2000

It has the following 20 published security problems.

SFlawFirstLast
LCVE-2022-35252: control code in cookie denial of service4.97.84.0
LCVE-2022-27776: Auth/cookie leak on redirect4.97.82.0
MCVE-2022-27774: Credential leak on redirect4.97.82.0
LCVE-2021-22876: Automatic referer leaks credentials7.1.17.75.0
LCVE-2020-8284: trusting FTP PASV responses4.07.73.0
LCVE-2018-1000007: HTTP authentication leak in redirects6.07.57.0
MCVE-2017-7407: --write-out out of buffer read6.57.53.1
MCVE-2016-9586: printf floating point buffer overflow5.47.51.0
HCVE-2016-8615: cookie injection for other servers4.97.50.3
MCVE-2016-8618: double free in curl_maprintf5.47.50.3
MCVE-2016-8624: invalid URL parsing with '#'6.07.50.3
HCVE-2016-5419: TLS session resumption client cert bypass5.07.50.0
HCVE-2016-0754: remote filename path traversal in curl tool for Windows4.07.46.0
HCVE-2015-3153: sensitive HTTP server headers also sent to proxies4.07.42.0
HCVE-2014-8150: URL request injection6.07.39.0
MCVE-2014-3613: cookie leak with IP address as domain4.07.37.1
HCVE-2013-1944: cookie domain tailmatch4.77.29.0
MCVE-2009-0037: Arbitrary File Access5.117.19.3
HCVE-2003-1605: Proxy Authentication Header Information Leakage4.57.10.6
CCVE-2000-0973: FTP Server Response Buffer Overflow6.07.4

Further details

CVE data for 7.2.1 provided as JSON.

Changelog for curl 7.2.1

See vulnerability summary for the previous release: 7.2 or the subsequent release: 7.3