Description
curl before version 7.52.0 is vulnerable to a buffer overflow when doing a large floating point output in libcurl's implementation of the printf() functions. If there are any application that accepts a format string from the outside without necessary input filtering, it could allow remote attacks.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-767-1 | curl security update |
Debian DLA |
DLA-1568-1 | curl security update |
EUVD |
EUVD-2016-10392 | curl before version 7.52.0 is vulnerable to a buffer overflow when doing a large floating point output in libcurl's implementation of the printf() functions. If there are any application that accepts a format string from the outside without necessary input filtering, it could allow remote attacks. |
Ubuntu USN |
USN-3441-1 | curl vulnerabilities |
Ubuntu USN |
USN-3441-2 | curl vulnerabilities |
References
History
Wed, 15 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-04-15T21:03:48.245Z
Reserved: 2016-11-23T00:00:00.000Z
Link: CVE-2016-9586
Updated: 2024-08-06T02:59:02.246Z
Status : Modified
Published: 2018-04-23T18:29:00.537
Modified: 2024-11-21T03:01:26.577
Link: CVE-2016-9586
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN