CVE-2019-3823: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 4.3% chance of exploitation in the next 30 days.

libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read contents will not be returned to the caller.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
  • Debian Debian Linux: version 9.0 only
  • Haxx Libcurl: from 7.34.0, before 7.64.0 (fixed in 7.64.0)
  • Netapp Clustered Data Ontap: any version
  • Oracle Communications Operations Monitor: version 3.4 only; version 4.0 only
  • Oracle HTTP Server: version 12.2.1.3.0 only
  • Oracle Secure Global Desktop: version 5.4 only

Published 2019-02-06. Last modified 2026-06-17.