{
  "schema_version": "1.5.0",
  "id": "CURL-CVE-2015-3144",
  "aliases": [
    "CVE-2015-3144"
  ],
  "summary": "hostname out of boundary memory access",
  "modified": "2026-05-19T11:21:50.00Z",
  "database_specific": {
    "package": "curl",
    "affects": "both",
    "URL": "https://curl.se/docs/CVE-2015-3144.json",
    "www": "https://curl.se/docs/CVE-2015-3144.html",
    "CWE": {
      "id": "CWE-124",
      "desc": "Buffer Underwrite ('Buffer Underflow')"
    },
    "last_affected": "7.41.0",
    "severity": "Medium"
  },
  "published": "2015-04-22T08:00:00.00Z",
  "affected": [
    {
      "ranges": [
        {
           "type": "SEMVER",
           "events": [
             {"introduced": "7.37.0"},
             {"fixed": "7.42.0"}
           ]
        },
        {
           "type": "GIT",
           "repo": "https://github.com/curl/curl.git",
           "events": [
             {"introduced": "5de8d84098db1bd24e7fffefbe14e81f2a05995a"},
             {"fixed": "0583e87ada7a3cfb10904ae4ab61b339582c5bd3"}
           ]
        }
      ],
      "versions": [
        "7.41.0", "7.40.0", "7.39.0", "7.38.0", "7.37.1", "7.37.0"
      ]
    }
  ],
  "credits": [
    {
      "name": "Hanno Böck",
      "type": "FINDER"
    },
    {
      "name": "Daniel Stenberg",
      "type": "REMEDIATION_DEVELOPER"
    }
  ],
  "details": "There is a private function in libcurl called `fix_hostname()` that removes a\ntrailing dot from the hostname if there is one. The function is called after\nthe hostname has been extracted from the URL libcurl has been told to act on.\n\nIf a URL is given with a zero-length hostname, like in \"http://:80\" or \":80\",\n`fix_hostname()` indexes the hostname pointer with a -1 offset (as it blindly\nassumes a non-zero length) and both read and assign that address.\n\nAt best, this gets unnoticed but can also lead to a crash or worse. We have\nnot researched further what kind of malicious actions that potentially this\ncould be used for."
}