Out-of-bounds read in libcurl - CVE-2018-1000005
Published: January 25, 2018
Vulnerability identifier: #VU10223
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1000005
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information or cause DoS condition on the target system.
The weakness exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted HTTP/2 trailer to trigger an out-of-bounds memory read error and cause the application to crash or obtain potentially sensitive information from services that echo back or otherwise use the trailers.
The weakness exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted HTTP/2 trailer to trigger an out-of-bounds memory read error and cause the application to crash or obtain potentially sensitive information from services that echo back or otherwise use the trailers.
Affected software
libcurl
Debian Linux
Arch Linux
Gentoo Linux
Amazon Linux AMI
Slackware Linux
Ubuntu
Fedora
curl (Alpine package)
curl
QLogic Virtual Fabric Extension Module for IBM BladeCenter
Debian Linux
Arch Linux
Gentoo Linux
Amazon Linux AMI
Slackware Linux
Ubuntu
Fedora
curl (Alpine package)
curl
QLogic Virtual Fabric Extension Module for IBM BladeCenter
How to mitigate CVE-2018-1000005
Update to version 7.58.0.
curl (Alpine package) - update to 7.58.0-r0
curl - addressed in versions 7.53.1-14.fc26, 7.55.1-9.fc27
QLogic Virtual Fabric Extension Module for IBM BladeCenter - update to 9.0.3.23.00
curl - addressed in versions 7.53.1-14.fc26, 7.55.1-9.fc27
QLogic Virtual Fabric Extension Module for IBM BladeCenter - update to 9.0.3.23.00
External References
Related Security Bulletins
- Multiple vulnerabilities in libcurl
- Slackware Linux update for curl
- Debian update for curl
- Arch Linux update for curl
- Arch Linux update for lib32-curl
- Arch Linux update for libcurl-compat
- Arch Linux update for libcurl-gnutls
- Arch Linux update for lib32-libcurl-gnutls
- Arch Linux update for lib32-libcurl-compat
- Ubuntu update for curl
- Amazon Linux AMI update for curl
- Gentoo update for cURL
- Out-of-bounds read in curl (Alpine package)
- Multiple vulnerabilities in Qlogic Virtual Fabric Extension Module for IBM BladeCenter Firmware Update
- Fedora 27 update for curl
- Fedora 26 update for curl