Medium severity4.3NVD Advisory· Published Jul 24, 2024· Updated Jun 17, 2026
CVE-2024-6874
CVE-2024-6874
Description
libcurl's URL API function curl_url_get() offers punycode conversions, to and from IDN. Asking to convert a name that is exactly 256 bytes, libcurl ends up reading outside of a stack based buffer when built to use the *macidn* IDN backend. The conversion function then fills up the provided buffer exactly - but does not null terminate the string.
This flaw can lead to stack contents accidently getting returned as part of the converted string.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- osv-coords4 versionspkg:rpm/opensuse/curl&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/curl&distro=openSUSE%20Tumbleweedpkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7
< 8.14.1-150600.4.28.1+ 3 more
- (no CPE)range: < 8.14.1-150600.4.28.1
- (no CPE)range: < 8.9.0-1.1
- (no CPE)range: < 8.14.1-150600.4.28.1
- (no CPE)range: < 8.14.1-150600.4.28.1
Patches
Vulnerability mechanics
References
5- hackerone.com/reports/2604391nvdExploitIssue TrackingTechnical Description
- www.openwall.com/lists/oss-security/2024/07/24/2nvdMailing ListThird Party Advisory
- curl.se/docs/CVE-2024-6874.htmlnvdVendor Advisory
- curl.se/docs/CVE-2024-6874.jsonnvdVendor Advisory
- security.netapp.com/advisory/ntap-20240822-0004/nvd
News mentions
0No linked articles in our index yet.