Back to Database
Status published
Medium
CVE-2018-16842
Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based...
Vulnerability Description
Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buffer over-read in the tool_msgs.c:voutf() function that may result in information exposure and denial of service.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-16842
Credits & Attribution
No credits recorded in the NVD database.
References
- https://security.gentoo.org/glsa/201903-03
- https://www.debian.org/security/2018/dsa-4331
- https://lists.debian.org/debian-lts-announce/2018/11/msg00005.html
- https://curl.haxx.se/docs/CVE-2018-16842.html
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16842
- http://www.securitytracker.com/id/1042014
- https://github.com/curl/curl/commit/d530e92f59ae9bb2d47066c3c460b25d2ffeb211
- https://usn.ubuntu.com/3805-2/
- https://usn.ubuntu.com/3805-1/
- https://access.redhat.com/errata/RHSA-2019:2181
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
More from The Curl Project
View All →CVE-2018-16840
A heap use-after-free flaw was found in curl versions from...
Medium
4.3
CVE-2018-16839
Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer...
Medium
4.3
CVE-2016-8625
curl before version 7.51.0 uses outdated IDNA 2003 standard to...
Medium
5.3
CVE-2016-8624
curl before version 7.51.0 doesn't parse the authority component of...
Medium
5.3
CVE-2016-8623
A flaw was found in curl before version 7.51.0. The...
Low
3.3
Affected Vendor
The Curl Project
View all reports →Affected Software
curl:
Vulnerable Versions:
from 7.14.1 to 7.61.1
Timeline
Official Publish:
October 31st, 2018
Last Modified:
April 15th, 2026
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L