MEDIUM SEVERITY

CVE-2017-9502

Curl vulnerability

CVSS
5.3
EPSS
3.3%
EPSS pct
87th
Exploited
No known
In curl before 7.54.1 on Windows and DOS, libcurl's default protocol function, which is the logic that allows an application to set which protocol libcurl should attempt to use when given a URL without a scheme part, had a flaw that could lead to it overwriting a heap based memory buffer with seven bytes. If the default protocol is specified to be FILE or a file: URL lacks two slashes, the given "URL" starts with a drive letter, and libcurl is built for Windows or DOS, then libcurl would copy the path 7 bytes off, so that the end of the given path would write beyond the malloc buffer (7 bytes being the length in bytes of the ascii string "file://").
Affected vendor
Haxx
Affected product
Curl
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Weakness type (CWE)
  • CWE-119 — Improper Restriction of Operations within Memory Bounds
Published
2017-06-14

Risk analysis

Based on its CVSS vector, this vulnerability is exploitable over the network, low attack complexity, requiring no privileges, no user interaction. Successful exploitation leads to low impact to availability.

Its EPSS score of 3.3% reflects a lower probability of exploitation activity in the wild over the next 30 days, placing it above 87% of all scored CVEs.

Check your external exposure to CVE-2017-9502

  • Confirm whether Haxx Curl is running on any internet-facing host or subdomain.
  • Match discovered service fingerprints against the version affected by CVE-2017-9502.
  • Prioritise remediation if the asset is public, business-critical, or near authentication/payment flows.

How ThreatPort helps with CVE-2017-9502

ThreatPort's external attack surface scanner checks your internet-facing assets — agentlessly, from the outside in — for the exposed services and versions that CVE-2017-9502 affects, then prioritises the finding by real risk using CISA KEV and FIRST.org EPSS.

Run a free external exposure scan

Are you exposed to CVE-2017-9502?

Run an instant, non-intrusive external scan to check your attack surface for CVE-2017-9502.

Start free scan

No credit card. Agentless.