CVE-2017-1000257

CRITICALNVD 9.19.1—
EchelonGraph scoreMEDIUM confidence

Score 9.1 from GitHub Security Advisory (severity: CRITICAL) published 2022-05-14. NVD baseline CVSS 9.1; sources differ by 0.0.

Triggered by: GitHub Security Advisory CVSS
Sources: epss, ghsa, nvd
9.1EG
EchelonGraph verdictPlan a fixSerious severity, but no confirmed exploitation yet.
  • High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS PROB: 6.2%CVSS: 9.1Exploit: None knownExposed services: —

A fix is available — apply it.

An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl would pass on that (non-existing) data with a pointer and the size (zero) to the deliver-data function. libcurl's deliver-data function treats zero as a magic number and invokes strlen() on the data to figure out the length. The strlen() is called on a heap based buffer that might not be zero terminated so libcurl might read beyond the end of it into whatever memory lies after (or just crash) and then deliver that to the application as if it was actually downloaded.

Internet exposure

The internet-exposure footprint is temporarily unavailable — the KEV-Exposure radar's record for this CVE could not be loaded just now. That is not a finding of zero exposed services; please retry shortly.

CVSS v3
9.1
EG Score
9.1CRITICALmedium confidence
EG Risk
58
EG Risk 58/100CISA SSVC

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity91% × 45%
Exploitation6% × 40%
Automatability100% × 15%
CISA SSVC: Track at low or medium mission impact; Attend at high (mission-essential systems).
Action: A fix is available. Apply it within your standard update timelines at low or medium mission impact and sooner than that at high.
EPSS PROB
6.2%
EPSS %ILE
93rd
KEV
Not listed

CISA SSVCTrack at low or medium mission impact; Attend at high (mission-essential systems).

A fix is available. Apply it within your standard update timelines at low or medium mission impact and sooner than that at high.

Exploitation none (CISA Vulnrichment) · Automatable yes (CISA Vulnrichment) · Technical impact partial (CISA Vulnrichment). Mission impact is CISA's Mission & Well-being decision point, and only you can judge it: high means the affected system is essential to your organisation's mission, or its compromise could cause irreversible harm to people. CISA's decision table

Published

October 31, 2017

Last Modified

June 17, 2026

Advisory Details

Enriched advisory details are temporarily unavailable — they could not be loaded just now. That is not a sign that none exist; please retry shortly.

Vendor Advisories for CVE-2017-1000257

Vendor advisories for this CVE are temporarily unavailable — the list could not be loaded just now. That is not a sign that none exist; please retry shortly.

Affected Packages

(29 across 29 ecosystems)
Alpine:v3.10(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-r0: fixed in 7.56.1-r0
—
Alpine:v3.11(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-r0: fixed in 7.56.1-r0
—
Alpine:v3.12(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-r0: fixed in 7.56.1-r0
—
Alpine:v3.13(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-r0: fixed in 7.56.1-r0
—
Alpine:v3.14(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-r0: fixed in 7.56.1-r0
—
Alpine:v3.15(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-r0: fixed in 7.56.1-r0
—
Alpine:v3.16(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-r0: fixed in 7.56.1-r0
—
Alpine:v3.17(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-r0: fixed in 7.56.1-r0
—
Alpine:v3.18(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-r0: fixed in 7.56.1-r0
—
Alpine:v3.19(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-r0: fixed in 7.56.1-r0
—
Alpine:v3.20(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-r0: fixed in 7.56.1-r0
—
Alpine:v3.21(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-r0: fixed in 7.56.1-r0
—
Alpine:v3.22(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-r0: fixed in 7.56.1-r0
—
Alpine:v3.23(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-r0: fixed in 7.56.1-r0
—
Alpine:v3.24(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-r0: fixed in 7.56.1-r0
—
Alpine:v3.3(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.55.0-r2: fixed in 7.55.0-r2
—
Alpine:v3.4(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.55.0-r2: fixed in 7.55.0-r2
—
Alpine:v3.5(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-r0: fixed in 7.56.1-r0
—
Alpine:v3.6(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-r0: fixed in 7.56.1-r0
—
Alpine:v3.7(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-r0: fixed in 7.56.1-r0
—
Alpine:v3.8(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-r0: fixed in 7.56.1-r0
—
Alpine:v3.9(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-r0: fixed in 7.56.1-r0
—
Debian:11(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-1: fixed in 7.56.1-1
—
Debian:12(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-1: fixed in 7.56.1-1
—
Debian:13(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-1: fixed in 7.56.1-1
—
Debian:14(1)
PackageVulnerable rangeFix by version rangeDependents
curl—
  • every version up to 7.56.1-1: fixed in 7.56.1-1
—
Debian:7(1)
PackageVulnerable rangeFix by version rangeDependents
curl7.26.0-1+wheezy10 ... 7.26.0-1+wheezy9 (20 versions)
  • every version up to 7.26.0-1+wheezy22: fixed in 7.26.0-1+wheezy22
—
Debian:8(1)
PackageVulnerable rangeFix by version rangeDependents
curl7.38.0-4 ... 7.38.0-4+deb8u6 (7 versions)
  • every version up to 7.38.0-4+deb8u7: fixed in 7.38.0-4+deb8u7
—
Debian:9(1)
PackageVulnerable rangeFix by version rangeDependents
curl7.52.1-5, 7.52.1-5+deb9u1
  • every version up to 7.52.1-5+deb9u2: fixed in 7.52.1-5+deb9u2
—

Frequently asked(5)

What is CVE-2017-1000257?
CVE-2017-1000257 is a critical vulnerability published on October 31, 2017. An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl would pass on that (non-existing) data with a pointer and the size (zero) to the deliver-data function. libcurl's deliver-data function treats zero as a…
When was CVE-2017-1000257 disclosed?
CVE-2017-1000257 was first published on October 31, 2017, with the most recent update on June 17, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2017-1000257 actively exploited?
CVE-2017-1000257 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 6.2% probability of exploitation in the next 30 days (93rd percentile of EPSS-scored CVEs).
What is the CVSS score of CVE-2017-1000257?
CVE-2017-1000257 has a CVSS v3 base score of 9.1 (NVD).
How do I remediate CVE-2017-1000257?
A fix for CVE-2017-1000257 is available: update to the fixed version the vendor names in its advisory.

Dependency Blast Radius

See which npm, PyPI, Go, and Maven packages are affected by CVE-2017-1000257

Explore →

Is Your Infrastructure Affected by CVE-2017-1000257?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.