CVE-2015-3144: Canonical Ubuntu Linux

High severity, CVSS 9.0. EPSS: 11% chance of exploitation in the next 30 days.

The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 14.10 only; version 15.04 only
  • Debian Debian Linux: version 7.0 only
  • Haxx Curl: version 7.37.0 only; version 7.37.1 only; version 7.38.0 only; version 7.39.0 only; version 7.40.0 only; version 7.41.0 only
  • Haxx Libcurl: version 7.37.0 only; version 7.37.1 only; version 7.38.0 only; version 7.39 only; version 7.40.0 only; version 7.41.0 only
  • Oracle MySQL Enterprise Monitor: up to and including 2.3.20; up to and including 3.0.22

Published 2015-04-24. Last modified 2026-06-17.