CVE-2018-16842: curl: Heap-based buffer over-read in the curl tool warning formatting

Severity: Critical

CVSS Score: 9.1

Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buffer over-read in the tool_msgs.c:voutf() function that may result in information exposure and denial of service.