CVE-2000-0973 describes a critical buffer overflow vulnerability in curl versions earlier than 6.0-1.1 and curl-ssl versions earlier than 6.0-1.2. This flaw allows unauthenticated remote attackers to execute arbitrary commands by triggering an excessively long error message. With a CVSS score of 10.0 (HIGH), this vulnerability is easily exploitable over the network with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog, exploit code is publicly available on ExploitDB, though there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0CPE matchmatch criteria | cpe:2.3:a:daniel_stenberg:curl:6.0:*:*:*:*:*:*:* | ||
6.1CPE matchmatch criteria | cpe:2.3:a:daniel_stenberg:curl:6.1:*:*:*:*:*:*:* | ||
6.1betaCPE matchmatch criteria | cpe:2.3:a:daniel_stenberg:curl:6.1beta:*:*:*:*:*:*:* | ||
6.3CPE matchmatch criteria | cpe:2.3:a:daniel_stenberg:curl:6.3:*:*:*:*:*:*:* | ||
6.4CPE matchmatch criteria | cpe:2.3:a:daniel_stenberg:curl:6.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
security flaw
Oct 13, 2000FTP Server Response Buffer Overflow
Oct 13, 2000CVE-2000-0973: FTP Server Response Buffer Overflow
Oct 13, 2000CVE-2000-0973: FTP Server Response Buffer Overflow
Oct 13, 2000CVE-2000-0973: FTP Server Response Buffer Overflow
Oct 13, 2000CVE-2000-0973: FTP Server Response Buffer Overflow
Oct 13, 2000CVE-2000-0973: FTP Server Response Buffer Overflow
Oct 13, 2000