Skip to content

Conversation

@npt-1707
Copy link

Hi Development Team,

I identified a potential vulnerability in a clone function in extensions/curl/curl-src/src/writeout.c sourced from curl/curl. This issue, originally reported in CVE-2017-7407, was resolved in the repository via this commit curl/curl@1890d59.

This PR applies the corresponding patch to fix the vulnerability in this codebase.

Please review at your convenience. Thank you!

@Kenzzer
Copy link
Member

Kenzzer commented Nov 24, 2025

PR is going stale, I was hoping for an explanation as to why this change is needed but 8 months have gone by.

The linked CVEC describes the issue roughly as follow :

[...] might allow physically proximate attackers to obtain sensitive information from process memory in opportunistic circumstances by reading a workstation screen [...]

SourceMod is a game server modding framework, its unlikely to be used in environments with 'workstation screen' but secondly and even more importantly the CVEC also states.

This flaw only exists in the command line tool.

Command line tool that isn't provided with sourcemod.

Overall this PR comes off as likely AI/script-generated through a most likely wide scan of github repositories making use of curl sources. (Other similar PRs can be found on the author's profile).

Given that this CVEC doesn't affect us, and given the author is most likely a bot with no chances for a reply, I'm closing this PR.

@Kenzzer Kenzzer closed this Nov 24, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants