HACKERONE

curl: Heap Buffer Overflow in Curl_memdup0() via CURLOPT_COPYPOSTFIELDS/CURLOPT_POSTFIELDSIZE Mismatch_H1:3292590

Description

Vulnerability description not provided

AI Analysis

A heap buffer overflow vulnerability in cURL's Curl_memdup0() function can occur due to a mismatch between CURLOPT_COPYPOSTFIELDS and CURLOPT_POSTFIELDSIZE. This could lead to memory corruption, potentially allowing arbitrary code execution or causing the application to crash. Users are advised to update to a patched version of cURL to mitigate this issue.

Visit Original Source

Basic Information

ID H1:3292590
Published Aug 9, 2025 at 02:32
Modified Aug 9, 2025 at 13:00

AI Assessment

AI Severity High
Vendor cURL Project Team
Product curl

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.