When libcurl is asked to perform automatic gzip...
High severity
Unreviewed
Published
Feb 5, 2025
to the GitHub Advisory Database
•
Updated Mar 7, 2025
Description
Published by the National Vulnerability Database
Feb 5, 2025
Published to the GitHub Advisory Database
Feb 5, 2025
Last updated
Mar 7, 2025
When libcurl is asked to perform automatic gzip decompression of
content-encoded HTTP responses with the
CURLOPT_ACCEPT_ENCODING
option,using zlib 1.2.0.3 or older, an attacker-controlled integer overflow would
make libcurl perform a buffer overflow.
References