CURL-CVE-2017-1000257

    Dashboard / Vulnerabilities / CURL-CVE-2017-1000257

    CURL-CVE-2017-1000257

    Published: 23 Oct 2017Last Modified: 27 May 2026

    Summary: IMAP FETCH response out of bounds read

    Details: libcurl contains a buffer overrun flaw in the IMAP handler. An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl would pass on that (non-existing) data with a pointer and the size (zero) to the deliver-data function. libcurl's deliver-data function treats zero as a magic number and invokes strlen() on the data to figure out the length. The strlen() is called on a heap based buffer that might not be null-terminated so libcurl might read beyond the end of it into whatever memory lies after (or crash) and then deliver that to the application as if it was actually downloaded.

    References:

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 7.20.0
    Fixed -7.56.1

    Affected versions

    7.56.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High