CVE-2024-6874 is a medium-severity vulnerability in libcurl's URL API function curl_url_get() when using the macidn IDN backend. It allows for out-of-bounds read on a stack-based buffer when converting a 256-byte punycode name, potentially exposing stack contents. The vulnerability has a CVSS score of 4.3 (Medium) with a network attack vector and low attack complexity, leading to a potential loss of confidentiality. There is no evidence of active exploitation, public exploit code, or significant community discussion, though it has been mentioned in one media article related to Siemens SINEC OS.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.8.0CPE matchmatch criteria | cpe:2.3:a:haxx:libcurl:8.8.0:*:*:*:*:*:*:* | ||
>= 8.8.0, <= 8.8.0CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.