Description
curl supports "globbing" of URLs, in which a user can pass a numerical range to have the tool iterate over those numbers to do a sequence of transfers. In the globbing function that parses the numerical range, there was an omission that made curl read a byte beyond the end of the URL if given a carefully crafted, or just wrongly written, URL. The URL is stored in a heap based buffer, so it could then be made to wrongly read something else instead of crashing. An example of a URL that triggers the flaw would be `http://ur%20[0-60000000000000000000`.
Published: 2017-10-04
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-3992-1 curl security update
EUVD EUVD EUVD-2017-1405 curl supports "globbing" of URLs, in which a user can pass a numerical range to have the tool iterate over those numbers to do a sequence of transfers. In the globbing function that parses the numerical range, there was an omission that made curl read a byte beyond the end of the URL if given a carefully crafted, or just wrongly written, URL. The URL is stored in a heap based buffer, so it could then be made to wrongly read something else instead of crashing. An example of a URL that triggers the flaw would be `http://ur%20[0-60000000000000000000`.
Ubuntu USN Ubuntu USN USN-3441-1 curl vulnerabilities
History

Thu, 16 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Haxx Curl
Redhat Rhel Software Collections
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-04-16T13:45:37.458Z

Reserved: 2017-10-03T00:00:00.000Z

Link: CVE-2017-1000101

cve-icon Vulnrichment

Updated: 2024-08-05T21:53:06.565Z

cve-icon NVD

Status : Deferred

Published: 2017-10-05T01:29:04.103

Modified: 2026-04-16T14:16:10.980

Link: CVE-2017-1000101

cve-icon Redhat

Severity : Low

Publid Date: 2017-08-09T00:00:00Z

Links: CVE-2017-1000101 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses