Sploitus

CVE-2024-6874

No indexed exploits for CVE-2024-6874 yet

libcurl's URL API function [curl_url_get()](https://curl.se/libcurl/c/curl_url_get.html) offers punycode conversions, to and from IDN. Asking to convert a name that is exactly 256 bytes, libcurl ends up reading outside of a stack based buffer when built to use the *macidn* IDN backend. The conversion function then fills up the provided buffer exactly - but does not null terminate the string. This flaw can lead to stack contents accidently getting returned as part of the converted string.

Affected products
Alt Linux, Astra Linux, Suse, Curl
Haxx Libcurl
= 8.8.0
CVSS 3.1
4.3 MEDIUM
EPSS
0.8% (53th percentile)
Weakness
CWE-125
NVD status
Modified
Published
2024-07-24
CVE-2024-6874 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-6874 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-6874 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.