CVE-2014-3707
The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to read sensitive memory information.
- Canonical Ubuntu Linux
- = 10.04, 12.04, 14.04, 14.10
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 5.1% (92th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2014-11-15
CVE-2014-3707 at NVD
1 known exploit for CVE-2014-3707
Proof-of-concept code and exploit modules indexed by Sploitus