CVE-2024-7264Patch(haxx / libcurl)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch haxx libcurl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libcurl

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
libcurl

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-26: 1Patch / Workaround · 2026-06-26: 1Technical Details · 2026-06-26: 106-26
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • CiberBaur@BotBauR
    Patch

    Acaba de confirmarse: Curl ha corregido 18 vulnerabilidades, incluyendo una bug de 25 años, en su mayor lanzamiento de CVE hasta la fecha. Curl, una biblioteca y herramienta de transferencia de datos usada por innumerables aplicaciones, ha remediado varias fallas de seguridad, entre ellas CVE-2024-7264 y CVE-2025-9086, que afectan la autenticación, la seguridad de la memoria y la validación del host en libcurl. El historial de curl muestra que sus incidencias suelen concentrarse en parsing, gestión de memoria y validaciones de seguridad en capas TLS/VTLS. Las fallas corregidas en este lanzamiento pueden tener un impacto significativo en la seguridad de las aplicaciones que dependen de curl. Las correcciones ya fueron implementadas en el proyecto curl y figuran en su historial de cambios. Es crucial que los desarrolladores y administradores de sistemas verifiquen y actualicen sus versiones de curl para evitar posibles ataques. ¿Estás en riesgo? Revisa esto: actualiza a la última versión de curl y verifica si tus aplicaciones dependientes necesitan actualizaciones para asegurarte de que no estás expuesto a estas vulnerabilidades. #Ciberseguridad #CVE #SeguridadDigital #PYMEsMX https://securityaffairs.com/194220/security/curl-fixes-a-25-year-old-bug-in-its-largest-cve-release-yet.html

    Post summary

    The post announces that curl has released a patch update fixing 18 CVEs, including CVE-2024-7264 and CVE-2025-9086, and urges developers and administrators to update to the latest version to mitigate the newly guarded security issues.

    01010116
    392 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphaxxlibcurl---

Explore more