CVE-2015-3144

critical
Published 2015-04-24 ยท Modified 2026-05-06
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
9.0

Description

The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker ยท View original โ†— ยท DFSG

CVE-2015-3144 NameCVE-2015-3144 DescriptionThe fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80." SourceCVE (at NVD; CERT, ENISA, LWN,โ€ฆ

CVE-2015-3144

NameCVE-2015-3144
DescriptionThe fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
curl (PTS)bullseye7.74.0-1.3+deb11u13fixed
bullseye (security)7.74.0-1.3+deb11u16fixed
bookworm7.88.1-10+deb12u14fixed
bookworm (security)7.88.1-10+deb12u5fixed
trixie8.14.1-2+deb13u3fixed
forky8.20.0-2fixed
sid8.20.0-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
curlsourcesqueeze(not affected)
curlsourcewheezy(not affected)
curlsourcejessie7.38.0-4+deb8u1
curlsource(unstable)7.42.0-1

Notes

[wheezy] - curl <not-affected> (Affects 7.37.0 to and including 7.41.0)
[squeeze] - curl <not-affected> (Affects 7.37.0 to and including 7.41.0)
http://curl.haxx.se/docs/adv_20150422D.html

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[wheezy] - curl <not-affected> (Affects 7.37.0 to and including 7.41.0)[squeeze] - curl <not-affected> (Affects 7.37.0 to and including 7.41.0)http://curl.haxx.se/docs/adv_20150422D.html

OS impact

ubuntu Ubuntu Affected 4 releases
VersionStatusFixed in
15.04 Affected โ€”
14.10 Affected โ€”
14.04 Affected โ€”
12.04 Affected โ€”
debian Debian Mixed 6 releases
VersionStatusFixed in
trixie Fixed 7.42.0-1
sid Fixed 7.42.0-1
forky Fixed 7.42.0-1
bullseye Fixed 7.42.0-1
bookworm Fixed 7.42.0-1
7.0 Affected โ€”

Application impact

VendorProductVersionsFixed
oracle oraclemysql_enterprise_monitor{"endIncluding":"2.3.20"}
haxxcurl7.37.0
haxxcurl7.37.1
haxxcurl7.38.0
haxxcurl7.39.0
haxxcurl7.40.0
haxxcurl7.41.0
haxxlibcurl7.37.0
haxxlibcurl7.37.1
haxxlibcurl7.38.0
haxxlibcurl7.39
haxxlibcurl7.40.0
haxxlibcurl7.41.0

References

CWEs

CWE-119

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.