{"schema_version":"1.7.5","id":"CURL-CVE-2006-1061","published":"2006-03-20T08:00:00Z","modified":"2026-05-19T11:21:50Z","aliases":["CVE-2006-1061"],"summary":"TFTP Packet Buffer Overflow","details":"libcurl uses the given file part of a TFTP URL in a manner that allows a\nmalicious user to overflow a heap-based memory buffer due to the lack of\nboundary check.\n\nThis overflow happens if you pass in a URL with a TFTP protocol prefix\n(\"tftp://\"), using a valid host and a path part that is longer than 512 bytes.\n\nThe affected flaw can be triggered by a redirect, if curl/libcurl is told to\nfollow redirects and an HTTP server points the client to a tftp URL with the\ncharacteristics described above.","affected":[{"ranges":[{"type":"SEMVER","events":[{"introduced":"7.15.0"},{"fixed":"7.15.3"}]}],"versions":["7.15.2","7.15.1","7.15.0"],"database_specific":{"source":"https://curl.se/docs/CURL-CVE-2006-1061.json"}}],"database_specific":{"CWE":{"desc":"Heap-based Buffer Overflow","id":"CWE-122"},"URL":"https://curl.se/docs/CVE-2006-1061.json","affects":"both","last_affected":"7.15.2","package":"curl","severity":"High","www":"https://curl.se/docs/CVE-2006-1061.html"},"credits":[{"name":"Ulf Harnhammar","type":"FINDER"},{"name":"Daniel Stenberg","type":"REMEDIATION_DEVELOPER"}]}