Critical severity9.8NVD Advisory· Published Jul 11, 2018· Updated Jun 17, 2026
CVE-2018-0500
CVE-2018-0500
Description
Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including curl 7.60.0 has a heap-based buffer overflow that might be exploitable by an attacker who can control the data that curl transmits over SMTP with certain settings (i.e., use of a nonstandard --limit-rate argument or CURLOPT_BUFFERSIZE value).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- osv-coords2 versionspkg:rpm/opensuse/curl&distro=openSUSE%20Tumbleweedpkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015
< 7.79.1-1.1+ 1 more
- (no CPE)range: < 7.79.1-1.1
- (no CPE)range: < 7.60.0-3.6.4
Patches
Vulnerability mechanics
References
6- github.com/curl/curl/commit/ba1dbd78e5f1ed67c1b8d37ac89d90e5e330b628nvdPatchThird Party Advisory
- curl.haxx.se/docs/adv_2018-70a2.htmlnvdExploitPatchVendor Advisory
- www.securitytracker.com/id/1041280nvdThird Party AdvisoryVDB Entry
- access.redhat.com/errata/RHSA-2018:2486nvdThird Party Advisory
- security.gentoo.org/glsa/201807-04nvdThird Party Advisory
- usn.ubuntu.com/3710-1/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.