Descriptioncurl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowingly issue network transfer requests to the wrong host.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
curl (PTS)jessie7.38.0-4+deb8u11vulnerable
jessie (security)7.38.0-4+deb8u16vulnerable
stretch, stretch (security)7.52.1-5+deb9u9fixed
bullseye, sid7.65.3-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs


[jessie] - curl <no-dsa> (the fix is too invasive)
[wheezy] - curl <no-dsa> (the fix is too invasive)

