Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2017-7407
Description:The ourWriteOut function in tool_writeout.c in curl 7.53.1 might allow physically proximate attackers to obtain sensitive information from process memory in opportunistic circumstances by reading a workstation screen during use of a --write-out argument ending in a '%' character, which leads to a heap-based buffer over-read.
Test IDs: 1.3.6.1.4.1.25623.1.1.2.2019.1697   1.3.6.1.4.1.25623.1.1.4.2017.2699.1   1.3.6.1.4.1.25623.1.0.890883   1.3.6.1.4.1.25623.1.1.4.2017.2701.1   1.3.6.1.4.1.25623.1.1.2.2019.1751   1.3.6.1.4.1.25623.1.0.872556   1.3.6.1.4.1.25623.1.1.4.2017.2700.1  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2017-7407
https://security.gentoo.org/glsa/201709-14
https://github.com/curl/curl/commit/1890d59905414ab84a35892b2e45833654aa5c13
RedHat Security Advisories: RHSA-2018:3558
https://access.redhat.com/errata/RHSA-2018:3558




© 1998-2025 E-Soft Inc. All rights reserved.