CVE-2010-0734

NameCVE-2010-0734
Descriptioncontent_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that requests automatic decompression, which might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact by sending crafted compressed data to an application that relies on the intended data-length limit.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-2023-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
curl (PTS)buster7.64.0-4+deb10u2fixed
buster (security)7.64.0-4+deb10u7fixed
bullseye7.74.0-1.3+deb11u9fixed
bullseye (security)7.74.0-1.3+deb11u10fixed
bookworm, bookworm (security)7.88.1-10+deb12u4fixed
trixie8.4.0-2fixed
sid8.5.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
curlsourcelenny7.18.2-8lenny4DSA-2023-1
curlsource(unstable)7.20.0-1low

Notes

https://www.openwall.com/lists/oss-security/2010/03/16/11
depends on the application that uses libcurl

Search for package or bug name: Reporting problems