suse · CVE-2017-8816

Quick triage

Priority: medium Published: 2021-05-30 13:56:20 UTC Updated: 2026-04-17 16:10:17 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2017-8816 severity moderate: SUSE including 319 source package names (0.9.1:libcurl4-7.37.0-37.11.3, 1.0.0:libcurl4-7.37.0-37.11.3, …), 414 product×package rows across 77 product lines (Container caasp/v4/default-http-backend, Container caasp/v4/dnsmasq-nanny, … (77 product lines)): Fixed 199, Known Affected 157, Known Not Affected 58.

Description:

The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vectors involving long user and password fields.

cvelogic Threat Intelligence