VDB

DEBIAN-CVE-2012-0036

DEBIAN-CVE-2012-0036 PUBLISHED

curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows remote attackers to conduct data-injection attacks via a crafted URL, as demonstrated by a CRLF injection attack on the (1) IMAP, (2) POP3, or (3) SMTP protocol.

Affected Products

VendorProductVersions
Debian:12curl0, 0, 0
Debian:13curl0, 0, 0
Debian:14curl0, 0, 0
Debian:11curl0, 0, 0

Timeline

  • Apr 13, 2012 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›