curl / Docs / Vulnerability table / 7.4 vulnerabilities

Vulnerabilities in curl 7.4

curl version 7.4 was released on October 16 2000

It has the following 23 published security problems.

FlawFrom versionTo and including
control code in cookie denial of service4.97.84.0
Auth/cookie leak on redirect4.97.82.0
Credential leak on redirect4.97.82.0
Automatic referer leaks credentials7.1.17.75.0
trusting FTP PASV responses4.07.73.0
HTTP authentication leak in redirects6.07.57.0
--write-out out of buffer read6.57.53.1
printf floating point buffer overflow5.47.51.0
cookie injection for other servers4.97.50.3
double free in curl_maprintf5.47.50.3
double free in krb5 code7.37.50.3
invalid URL parsing with '#'6.07.50.3
TLS session resumption client cert bypass5.07.50.0
remote filename path traversal in curl tool for Windows4.07.46.0
sensitive HTTP server headers also sent to proxies4.07.42.0
URL request injection6.07.39.0
cookie leak with IP address as domain4.07.37.1
cookie domain tailmatch4.77.29.0
embedded zero in cert name7.47.19.5
Arbitrary File Access5.117.19.3
Authentication Buffer Overflows7.37.13.0
Proxy Authentication Header Information Leakage4.57.10.6
FTP Server Response Buffer Overflow6.07.4

Futher details

CVE data for 7.4 provided as JSON.

Changelog for curl 7.4

See vulnerability summary for the previous release: 7.3 or the subsequent release: 7.4.1