ZeroHour

CVE-2018-1000122

CVSS 3.0
9.1 critical
EPSS
9%p95
Published
()
Modified
Description

A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of service or information leakage

Vendors
debiancanonicalhaxxredhatoracle
Products
debian linux, ubuntu linux, curl, enterprise linux desktop, enterprise linux server, enterprise linux workstation, communications webrtc session controller, enterprise manager ops center, peoplesoft enterprise peopletools
Weakness
CWE-125
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.