Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buffer over-read in the tool_msgs.c:voutf() function that may result in information exposure and denial of service.
{ "vanir_signatures": [ { "id": "CVE-2018-16842-1bc8b2d6", "source": "https://github.com/curl/curl/commit/d530e92f59ae9bb2d47066c3c460b25d2ffeb211", "deprecated": false, "signature_version": "v1", "signature_type": "Line", "digest": { "threshold": 0.9, "line_hashes": [ "168815568103819800894446565004067456537", "228111618259869147888575535538857014400", "339861644007337486665567803047408870040", "172320610373815332630135197132714421772" ] }, "target": { "file": "src/tool_msgs.c" } }, { "id": "CVE-2018-16842-ea38dff0", "source": "https://github.com/curl/curl/commit/d530e92f59ae9bb2d47066c3c460b25d2ffeb211", "deprecated": false, "signature_version": "v1", "signature_type": "Function", "digest": { "length": 701.0, "function_hash": "276247327338978490978930240644272334443" }, "target": { "file": "src/tool_msgs.c", "function": "voutf" } } ] }