CURL-CVE-2015-3144

    Dashboard / Vulnerabilities / CURL-CVE-2015-3144

    CURL-CVE-2015-3144

    Published: 22 Apr 2015Last Modified: 27 May 2026
    Aliases:

    Summary: hostname out of boundary memory access

    Details: There is a private function in libcurl called `fix_hostname()` that removes a trailing dot from the hostname if there is one. The function is called after the hostname has been extracted from the URL libcurl has been told to act on. If a URL is given with a zero-length hostname, like in "http://:80" or ":80", `fix_hostname()` indexes the hostname pointer with a -1 offset (as it blindly assumes a non-zero length) and both read and assign that address. At best, this gets unnoticed but can also lead to a crash or worse. We have not researched further what kind of malicious actions that potentially this could be used for.

    References:

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 7.37.0
    Fixed -7.42.0

    Affected versions

    7.41.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High