← Vulnerability feed

Vulnerability record · CVE-2024-7264 · published 31 July 2024

CVE-2024-7264: Haxx libcurl out-of-bounds read vulnerability

Haxx · Libcurl

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.

6.5 CVSS 3.1 Medium EPSS 17% · top 3.0% CWE-125 · Out-of-bounds read
6.5CVSS 3.1 base score
17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
9References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-7264 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-38545curl SOCKS5 proxy handshake heap buffer overflowcurl contains a heap-based out-of-bounds write (CWE-787) in the SOCKS5 proxy handshake. When a host name longer than 255 bytes is passed for proxy-si…EPSS 78%analysed9.8CVE-2019-3822Haxx libcurl stack-based buffer overflow vulnerabilitylibcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (…EPSS 13%9.8CVE-2018-14618Haxx libcurl heap-based buffer overflow vulnerabilitycurl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multipl…EPSS 11%9.8CVE-2016-8622Haxx libcurl heap-based buffer overflow vulnerabilityThe URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if this function would be made to …EPSS 4.7%9.8CVE-2017-8816Haxx curl integer overflow vulnerabilityThe NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow…EPSS 8.5%9.8CVE-2017-8817Haxx curl out-of-bounds read vulnerabilityThe FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application …EPSS 11%9.8CVE-2017-8818Haxx curl memory buffer overflow vulnerabilitycurl and libcurl before 7.57.0 on 32-bit platforms allow attackers to cause a denial of service (out-of-bounds access and application crash) or possi…EPSS 3.8%9.8CVE-2016-7167Fedoraproject fedora integer overflow vulnerabilityMultiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) curl_unescape, and (4) curl_easy_unescape functions in libcurl before 7.…EPSS 12%

Source: NIST National Vulnerability Database (record CVE-2024-7264), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.