CVE-2017-1000254 describes a heap out-of-bounds read vulnerability in haxx libcurl, affecting versions introduced after March 2005. When connecting to an FTP server, libcurl's parser for the PWD command's 257 response could fail to null-terminate the directory path if the server's response lacked a closing double quote. This could lead to a crash or incorrect data access when libcurl subsequently uses the malformed path. Rated with a CVSS v3.0 score of 7.5 (HIGH), this vulnerability has a network attack vector and low attack complexity, requiring no privileges or user interaction. The primary impact is high availability, as a malicious FTP server could intentionally cause client crashes, effectively preventing libcurl-based clients from functioning. There is no evidence of active exploitation, and no exploit code is publicly available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting it has not garnered significant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.7CPE matchmatch criteria | cpe:2.3:a:haxx:libcurl:7.7:*:*:*:*:*:*:* | ||
7.7.1CPE matchmatch criteria | cpe:2.3:a:haxx:libcurl:7.7.1:*:*:*:*:*:*:* | ||
7.7.2CPE matchmatch criteria | cpe:2.3:a:haxx:libcurl:7.7.2:*:*:*:*:*:*:* | ||
7.7.3CPE matchmatch criteria | cpe:2.3:a:haxx:libcurl:7.7.3:*:*:*:*:*:*:* | ||
7.8CPE matchmatch criteria | cpe:2.3:a:haxx:libcurl:7.8:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.