CVE-2025-5399 log
Source |
|
Severity | Low |
Remote | Yes |
Type | Denial of service |
Description | Due to a mistake in libcurl's WebSocket code, a malicious server can send a particularly crafted packet which makes libcurl get trapped in an endless busy-loop. There is no other way for the application to escape or exit this loop other than killing the thread/process. This might be used to DoS libcurl-using application. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-2895 | curl | 8.14.0-2 | 8.14.1-1 | Low | Fixed |
Date | Advisory | Group | Package | Severity | Type |
---|---|---|---|---|---|
05 Jun 2025 | ASA-202506-2 | AVG-2895 | curl | Low | denial of service |
References |
---|
https://curl.se/docs/CVE-2025-5399.html https://github.com/curl/curl/commit/d1145df24de8f80e6b16 |