CVE-2017-8817: Debian Linux
Critical severity, CVSS 9.8. EPSS: 11.2% chance of exploitation in the next 30 days.
The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a string that ends with an '[' character.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Haxx Curl: from 7.21.0, up to and including 7.56.1
- Haxx Libcurl: after 7.21.0, up to and including 7.56.1
Published 2017-11-29. Last modified 2026-06-17.