CVE-2018-0500 describes a critical heap-based buffer overflow in Curl_smtp_escape_eob within curl versions 7.54.1 through 7.60.0, impacting canonical and haxx curl and Ubuntu Linux. This vulnerability, rated 9.8 CVSS (Critical), allows for remote exploitation with low attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. While the EPSS score is low and it's not on the KEV catalog, there is currently no public exploit code available, nor has it garnered significant community or media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.54.1, <= 7.60.0CPE matchmatch criteria | cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* | ||
17.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
curl: Heap-based buffer overflow in Curl_smtp_escape_eob() when uploading data over SMTP
Jul 11, 2018SMTP send heap buffer overflow
Jul 11, 2018SMTP send heap buffer overflow
Jul 11, 2018