{"id":"UBUNTU-CVE-2018-1000005","details":"libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers. It was reported (https://github.com/curl/curl/pull/2231) that reading an HTTP/2 trailer could mess up future trailers since the stored size was one byte less than required. The problem is that the code that creates HTTP/1-like headers from the HTTP/2 trailer data once appended a string like `:` to the target buffer, while this was recently changed to `: ` (a space was added after the colon) but the following math wasn't updated correspondingly. When accessed, the data is read out of bounds and causes either a crash or that the (too large) data gets passed to client write. This could lead to a denial-of-service situation or an information disclosure if someone has a service that echoes back or uses the trailers for something.","modified":"2026-04-22T11:38:45.753054Z","published":"2018-01-24T00:00:00Z","related":["USN-3554-1"],"upstream":["CVE-2018-1000005"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2018-1000005"},{"type":"REPORT","url":"https://github.com/curl/curl/pull/2231"},{"type":"REPORT","url":"https://curl.haxx.se/docs/adv_2018-824a.html"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-3554-1"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2018-1000005"}],"affected":[{"package":{"name":"curl","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/curl@7.47.0-1ubuntu2.6?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.47.0-1ubuntu2.6"}]}],"versions":["7.43.0-1ubuntu2","7.45.0-1ubuntu1","7.46.0-1ubuntu1","7.47.0-1ubuntu1","7.47.0-1ubuntu2","7.47.0-1ubuntu2.1","7.47.0-1ubuntu2.2","7.47.0-1ubuntu2.3","7.47.0-1ubuntu2.4","7.47.0-1ubuntu2.5"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"curl","binary_version":"7.47.0-1ubuntu2.6"},{"binary_name":"libcurl3","binary_version":"7.47.0-1ubuntu2.6"},{"binary_name":"libcurl3-gnutls","binary_version":"7.47.0-1ubuntu2.6"},{"binary_name":"libcurl3-nss","binary_version":"7.47.0-1ubuntu2.6"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-1000005.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}