VDB
JLSEC-2025-34
JLSEC-2025-34
PUBLISHED
CVSS 9.800000190734863 CRITICAL
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake.
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Julia | CURL_jll | 0, 0 |
| Julia | CURL_jll | 0 |
| Julia | LibCURL_jll | 7.70.0+0 |
| Julia | LibCURL_jll | 7.70.0+0, 7.70.0+0 |
Timeline
- Oct 10, 2025 CVE Published
- Jul 18, 2026 CVE Updated
References
- http://seclists.org/fulldisclosure/2024/Jan/34 url
- http://seclists.org/fulldisclosure/2024/Jan/37 url
- http://seclists.org/fulldisclosure/2024/Jan/38 url
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html url
- https://cert-portal.siemens.com/productcert/html/ssa-093430.html url
- https://cert-portal.siemens.com/productcert/html/ssa-507364.html url
- https://cert-portal.siemens.com/productcert/html/ssa-832273.html url
- https://cert-portal.siemens.com/productcert/html/ssa-943925.html url
- https://curl.se/docs/CVE-2023-38545.html url
- https://forum.vmssoftware.com/viewtopic.php?f=8&t=8868 url
- https://github.com/UTsweetyfish/CVE-2023-38545 url
- https://github.com/bcdannyboy/CVE-2023-38545 url
- https://github.com/dbrugman/CVE-2023-38545-POC url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OGMXNRNSJ4ETDK6FRNU3J7SABXPWCHSQ/ url
- https://security.netapp.com/advisory/ntap-20231027-0009/ url
- https://security.netapp.com/advisory/ntap-20240201-0005/ url
- https://support.apple.com/kb/HT214036 url
- https://support.apple.com/kb/HT214057 url
- https://support.apple.com/kb/HT214058 url
- https://support.apple.com/kb/HT214063 url
…and 1 more