PublicDateAtUSN: 2017-04-03 Candidate: CVE-2017-7407 PublicDate: 2017-04-03 20:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7407 https://curl.haxx.se/docs/adv_20170403.html https://ubuntu.com/security/notices/USN-3441-1 https://ubuntu.com/security/notices/USN-3441-2 Description: The ourWriteOut function in tool_writeout.c in curl 7.53.1 might allow physically proximate attackers to obtain sensitive information from process memory in opportunistic circumstances by reading a workstation screen during use of a --write-out argument ending in a '%' character, which leads to a heap-based buffer over-read. Ubuntu-Description: Notes: tyhicks> Affected code is in src/writeout.c in older releases mdeslaur> first commit is in 7.52.1-4, second one isn't Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=859500 Priority: negligible Discovered-by: Brian Carpenter Assigned-to: mdeslaur CVSS: nvd: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N [2.4 LOW] Patches_curl: upstream: https://github.com/curl/curl/commit/1890d59905414ab84a35892b2e45833654aa5c13 upstream: https://github.com/curl/curl/commit/8e65877870c1fac920b65219adec720df810aab9 upstream_curl: released (7.54.0,7.52.1-4) precise_curl: ignored (reached end-of-life) precise/esm_curl: released (7.22.0-3ubuntu4.18) trusty_curl: released (7.35.0-1ubuntu2.11) trusty/esm_curl: released (7.35.0-1ubuntu2.11) vivid/stable-phone-overlay_curl: ignored (reached end-of-life) vivid/ubuntu-core_curl: ignored (reached end-of-life) xenial_curl: released (7.47.0-1ubuntu2.3) esm-infra/xenial_curl: released (7.47.0-1ubuntu2.3) yakkety_curl: ignored (reached end-of-life) zesty_curl: released (7.52.1-4ubuntu1.2) artful_curl: not-affected (7.55.1-1ubuntu1) devel_curl: not-affected (7.55.1-1ubuntu1)