Red Hat Bugzilla – Bug 1439190
CVE-2017-7407 curl: --write-out out of bounds read
Last modified: 2018-01-11 07:32:34 EST
The ourWriteOut function in tool_writeout.c in curl might allow physically proximate attackers to obtain sensitive information from process memory in opportunistic circumstances by reading a workstation screen during use of a --write-out argument ending in a '%' character, which leads to a heap-based buffer over-read. External References: https://curl.haxx.se/docs/adv_20170403.html Upstream patches: https://github.com/curl/curl/commit/1890d59905414ab84a https://github.com/curl/curl/commit/8e65877870c1
Created curl tracking bugs for this issue: Affects: fedora-all [bug 1439191] Created mingw-curl tracking bugs for this issue: Affects: epel-7 [bug 1439193] Affects: fedora-all [bug 1439192]