CVE-2019-3823: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 4.3% chance of exploitation in the next 30 days.
libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read contents will not be returned to the caller.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
- Debian Debian Linux: version 9.0 only
- Haxx Libcurl: from 7.34.0, before 7.64.0 (fixed in 7.64.0)
- Netapp Clustered Data Ontap: any version
- Oracle Communications Operations Monitor: version 3.4 only; version 4.0 only
- Oracle HTTP Server: version 12.2.1.3.0 only
- Oracle Secure Global Desktop: version 5.4 only
Published 2019-02-06. Last modified 2026-06-17.