CVE-2016-8618

Severity CVSS v4.0:
Pending analysis
Type:
CWE-415 Double Free
Publication date:
31/07/2018
Last modified:
07/11/2023

Description

The libcurl API function called `curl_maprintf()` before version 7.51.0 can be tricked into doing a double-free due to an unsafe `size_t` multiplication, on systems using 32 bit `size_t` variables.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* 7.51.0 (excluding)