Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2025-38

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Tim...

JLSEC Published
Modified
Affected Packages
CURL_jll < 8.9.1+0
LibCURL_jll < 8.9.1+0
Aliases / Upstream
CVE-2024-7264

libcurl's ASN1 parser code has the GTime2str() function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the time fraction, leading to a strlen() getting performed on a pointer to a heap buffer area that is not (purposely) null terminated.

This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when CURLINFO_CERTINFO is used.

References