curl / Docs / Vulnerability table / 7.65.0 vulnerabilities

Vulnerabilities in curl 7.65.0

curl version 7.65.0 was released on May 22 2019. The following 6 security problems are known to exist in this version.

FlawFrom versionTo and includingCVECWE
wrong connect-only connection7.29.07.71.1CVE-2020-8231CWE-825: Expired Pointer Dereference
curl overwrite local file with -J7.20.07.70.0CVE-2020-8177CWE-641: Improper Restriction of Names for Files and Other Resources
Partial password leak over DNS on HTTP redirect7.62.07.70.0CVE-2020-8169CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
FTP-KRB double-free7.52.07.65.3CVE-2019-5481CWE-415: Double Free
TFTP small blocksize heap buffer overflow7.19.47.65.3CVE-2019-5482CWE-122: Heap-based Buffer Overflow
Windows OpenSSL engine code injection7.61.07.65.1CVE-2019-5443CWE-94: Code Injection

Changelog for curl 7.65.0

See vulnerability summary for the previous release: 7.64.1 or the subsequent release: 7.65.1