CVE-2015-3144: Canonical Ubuntu Linux
High severity, CVSS 9.0. EPSS: 11% chance of exploitation in the next 30 days.
The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 14.10 only; version 15.04 only
- Debian Debian Linux: version 7.0 only
- Haxx Curl: version 7.37.0 only; version 7.37.1 only; version 7.38.0 only; version 7.39.0 only; version 7.40.0 only; version 7.41.0 only
- Haxx Libcurl: version 7.37.0 only; version 7.37.1 only; version 7.38.0 only; version 7.39 only; version 7.40.0 only; version 7.41.0 only
- Oracle MySQL Enterprise Monitor: up to and including 2.3.20; up to and including 3.0.22
Published 2015-04-24. Last modified 2026-06-17.