CVE-2024-6874

Public on 2024-07-24
Modified on 2024-08-06
Description
CVE-2024-6874 is a serious security flaw in libcurl's curl_url_get() function, used for converting international domain names. When processing a name exactly 256 bytes long, it reads beyond its buffer and fails to null-terminate the string, potentially exposing or modifying stack data. This vulnerability is easy to exploit remotely without special permissions or user interaction, making it a important-severity issue with a CVSS score of 7.2. Users should apply security patches to mitigate this risk.
Severity
Important severity
Important
CVSS v3 Base Score
7.2
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
HAQM Linux 1 curl Not Affected
HAQM Linux 2 - Core curl Not Affected
HAQM Linux 2023 curl Not Affected
HAQM Linux 1 python-pycurl Not Affected
HAQM Linux 2 - Core python-pycurl Not Affected
HAQM Linux 2023 python-pycurl Not Affected
HAQM Linux 2 - Core python3-pycurl Not Affected

CVSS Scores

Score Type Score Vector
HAQM Linux CVSSv3 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
NVD CVSSv3 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N