CVE-2013-2174: Canonical Ubuntu Linux

Medium severity, CVSS 6.8. EPSS: 10.7% chance of exploitation in the next 30 days.

Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string ending in a "%" (percent) character.

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 12.10 only; version 13.04 only
  • Haxx Curl: version 7.7 only; version 7.7.1 only; version 7.7.2 only; version 7.7.3 only; version 7.8 only; version 7.8.1 only; …
  • Haxx Libcurl: version 7.7 only; version 7.7.1 only; version 7.7.2 only; version 7.7.3 only; version 7.8 only; version 7.8.1 only; …
  • Opensuse Opensuse: version 11.4 only
  • Red Hat Enterprise Linux: version 5 only; version 6.0 only

Published 2013-07-31. Last modified 2026-06-16.