CVE-2024-7264 is a vulnerability in haxx libcurl's ASN.1 parser, specifically within the GTime2str() function. An improperly formatted ASN.1 Generalized Time field can cause the parser to attempt a strlen() operation on a non-null-terminated heap buffer, leading to a crash or the disclosure of heap contents if CURLINFO_CERTINFO is used. This medium-severity vulnerability (CVSS 6.5) requires user interaction (UI:R) and could result in a denial of service (A:H) or information disclosure (C:N). There is currently no evidence of active exploitation, public exploit code, or significant community discussion, with only one article mentioning it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.32.0, < 8.9.1CPE matchmatch criteria | cpe:2.3:a:haxx:libcurl:*:*:*:*:*:*:*:* | ||
>= 7.32.0, <= 7.32.0CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 7.33.0, <= 7.33.0CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 7.34.0, <= 7.34.0CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 7.35.0, <= 7.35.0CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk Enterprise - July 2025
Jul 7, 2025CVE-2024-7264
Dec 10, 2024CVE-2024-7264
Nov 12, 2024HP ThinPro 8.1 SP4 Security Updates
Oct 29, 2024HP ThinPro 8.1 SP4 Security Updates
Oct 29, 2024CVE-2024-7264
Oct 8, 2024Curl advisory
Aug 26, 2024Curl advisory
Aug 26, 2024Curl advisory
Aug 26, 2024Curl advisory
Aug 26, 2024Curl advisory
Aug 26, 2024Curl advisory
Aug 26, 2024Curl advisory
Aug 26, 2024Curl advisory
Aug 26, 2024curl: libcurl: ASN.1 date parser overread
Jul 31, 2024ASN.1 date parser overread
Jul 31, 2024ASN.1 date parser overread
Jul 9, 2024About the security content of visionOS 26.2 - Apple Support
About the security content of watchOS 26.2 - Apple Support
About the security content of iOS 18.7.3 and iPadOS 18.7.3 - Apple Support
About the security content of tvOS 26.2 - Apple Support
About the security content of macOS Sonoma 14.8.3 - Apple Support
About the security content of macOS Sequoia 15.7.3 - Apple Support
About the security content of macOS Tahoe 26.2 - Apple Support
About the security content of iOS 26.2 and iPadOS 26.2 - Apple Support