Red Hat Bugzilla – Bug 1536013
CVE-2018-1000005 curl: Out-of-bounds read in code handling HTTP/2 trailers
Last modified: 2018-04-24 02:59:30 EDT
An out-of-bounds read in code handling HTTP/2 trailers was found. This could lead to a denial-of-service or an information disclosure in some circumstances. Affected versions: libcurl 7.49.0 to and including 7.57.0 Not affected versions: libcurl < 7.49.0 and >= 7.58.0 Upstream bug report: https://github.com/curl/curl/pull/2231 Upstream patch: https://github.com/curl/curl/commit/fa3dbb9a147488a294.patch
Acknowledgments: Name: the Curl project Upstream: Zhouyihai Ding
External References: https://curl.haxx.se/docs/adv_2018-824a.html