CVE-2018-16890: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 5.4% chance of exploitation in the next 30 days.
libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a malicious or broken NTLM server could trick libcurl to accept a bad length + offset combination that would lead to a buffer read out-of-bounds.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
- Debian Debian Linux: version 9.0 only
- F5 BIG-IP Access Policy Manager: from 13.1.0, up to and including 13.1.3; from 14.0.0, up to and including 14.1.2; from 15.0.0, up to and including 15.0.1
- Haxx Libcurl: from 7.36.0, before 7.64.0 (fixed in 7.64.0)
- Netapp Clustered Data Ontap: any version
- Oracle Communications Operations Monitor: version 3.4 only; version 4.0 only
- Oracle HTTP Server: version 12.2.1.3.0 only
- Oracle Secure Global Desktop: version 5.4 only
- Red Hat Enterprise Linux: version 8.0 only
- Siemens Sinema Remote Connect Client: up to and including 2.0
Published 2019-02-06. Last modified 2026-06-17.