CVE-2018-16890 is a heap buffer out-of-bounds read vulnerability in libcurl versions 7.36.0 to before 7.64.0, affecting various products including Canonical, Debian, and Oracle. A malicious NTLM server can exploit an integer overflow in the NTLM type-2 message handling to cause a denial of service. Rated 7.5 HIGH on CVSS, this vulnerability has a network attack vector and low attack complexity, but no confidentiality or integrity impact. There is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.36.0, < 7.64.0CPE matchmatch criteria | cpe:2.3:a:haxx:libcurl:*:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* | ||
18.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.