FlawAtlas
Search the atlas
CVE-2016-8621 Moderate

curl_getdate read out of bounds

The `curl_getdate` converts a given date string into a numerical timestamp and it supports a range of different formats and possibilities to express a date and time. The underlying date parsing function is also used internally when parsing for example HTTP cookies (possibly received from remote servers) and it can be used when doing conditional HTTP requests. The date parser function uses the libc `sscanf()` function at two places, with the parsing strings `%02d:%02d` and `%02d:%02d:%02d`. The intent being that it would parse either a string with HH:MM (two digits colon two digits) or `HH:MM:SS` (two digits colon two digits colon two digits). If instead the piece of time that was sent in had the final digit cut off, thus ending with a single-digit, the date parser code would advance its read pointer one byte too much and end up reading out of bounds.

Exploit probability 5.2%
Published November 2, 2016
Required by Not available
Last source change May 27, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

139 explicit affected versions

Unknown Unknown

161 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2016-8621

The `curl_getdate` function in curl before version 7.51.0 is vulnerable to an out of bounds read if it receives an input with one digit short.

View original source
Open Source Vulnerabilities CURL-CVE-2016-8621

The `curl_getdate` converts a given date string into a numerical timestamp and it supports a range of different formats and possibilities to express a date and time. The underlying date parsing function is also used internally when parsing for example HTTP cookies (possibly received from remote servers) and it can be used when doing conditional HTTP requests. The date parser function uses the libc `sscanf()` function at two places, with the parsing strings `%02d:%02d` and `%02d:%02d:%02d`. The intent being that it would parse either a string with HH:MM (two digits colon two digits) or `HH:MM:SS` (two digits colon two digits colon two digits). If instead the piece of time that was sent in had the final digit cut off, thus ending with a single-digit, the date parser code would advance its read pointer one byte too much and end up reading out of bounds.

View original source

05 / REFERENCES

Further evidence