curl / Docs / Vulnerability table / 7.65.2 vulnerabilities

Vulnerabilities in curl 7.65.2

curl version 7.65.2 was released on July 17 2019. The following 5 security problems are known to exist in this version.

FlawFrom versionTo and includingCVECWE
wrong connect-only connection7. Expired Pointer Dereference
curl overwrite local file with -J7. Improper Restriction of Names for Files and Other Resources
Partial password leak over DNS on HTTP redirect7. Exposure of Sensitive Information to an Unauthorized Actor
FTP-KRB double-free7. Double Free
TFTP small blocksize heap buffer overflow7. Heap-based Buffer Overflow

Changelog for curl 7.65.2

See vulnerability summary for the previous release: 7.65.1 or the subsequent release: 7.65.3