CVE-2024-7264
MEDIUM EPSS 96.5%
Published Jul 31, 20241y ago · Modified Jun 17, 20262w ago
6.5 CVSS 3.1
Published Jul 31, 2024 1y ago
Last Modified Jun 17, 2026 2w ago
Description
libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality None
Integrity None
Availability High
Threat Intelligence
EPSS Exploit Probability
96.5% percentile
Exploit & Patch Status
Public Exploit Known
No Patch Available
Weaknesses 1
CWE-125 Out-of-bounds Read Memory Safety
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| haxx | libcurl | * | ≥7.32.0 – <8.9.1 |
References 8
- openwall.com http://www.openwall.com/lists/oss-security/2024/07/31/1
- curl.se https://curl.se/docs/CVE-2024-7264.html
- curl.se https://curl.se/docs/CVE-2024-7264.json
- github.com https://github.com/curl/curl/commit/27959ecce75cdb2809c0bdb3286e60e08fadb519
- hackerone.com https://hackerone.com/reports/2629968
- security.netapp.com https://security.netapp.com/advisory/ntap-20240828-0008/
- security.netapp.com https://security.netapp.com/advisory/ntap-20241025-0006/
- security.netapp.com https://security.netapp.com/advisory/ntap-20241025-0010/
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.