CVE-2015-3237

UnknownEPSS 9.33%

Last modified

CVE-2015-3237 is a vulnerability of currently unknown severity. The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.. EPSS estimates a 9.33% chance of exploitation in the next 30 days.

Description

The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.

Metrics

EPSS Probability
9.33%

94.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HaxxCurl7.40.0
HaxxCurl7.41.0
HaxxCurl7.42.0
HaxxCurl7.42.1
HaxxLibcurl7.40.0
HaxxLibcurl7.41.0
HaxxLibcurl7.42.0
HaxxLibcurl7.42.1
HpSystem Management Homepage<= 7.5.3.1
OracleEnterprise Manager Ops Center12.1.4
OracleEnterprise Manager Ops Center12.2.2
OracleEnterprise Manager Ops Center12.3.2
OracleGlassfish Server3.0.1
OracleGlassfish Server3.1.2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-3237?
The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.
How severe is CVE-2015-3237?
Severity scoring for CVE-2015-3237 is pending analysis. The EPSS model estimates a 9.33% probability of exploitation in the next 30 days.
How do I fix CVE-2015-3237?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-3237?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST