Integer overflow in libcurl - CVE-2018-16839

 

Integer overflow in libcurl - CVE-2018-16839

Published: November 1, 2018 / Updated: November 1, 2018


Vulnerability identifier: #VU15671
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-16839
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in processing the Curl_auth_create_plain_message name and password when handling malicious input. A remote unauthenticated attacker can send specially crafted SASL password data, trigger memory corruption and execute arbitrary code with elevated privileges. The affected function can be invoked using POP3(S), IMAP(S), or SMTP(S).

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

libcurl
Arch Linux
Gentoo Linux
Amazon Linux AMI
Slackware Linux
Opensuse
Fedora
curl (Alpine package)
curl (Debian package)
curl
Secured Component Verification (SCV)
EMC ECS
Watson Studio on Cloud Pak for Data
Dell PowerProtect Cyber Recovery
IBM Cloud Transformation Advisor

How to mitigate CVE-2018-16839

Update to version 7.62.0.

libcurl - update to 7.62.0
curl (Debian package) - update to 7.52.1-5+deb9u8
curl (Alpine package) - addressed in versions 7.61.1-r1, 7.62.0-r0
Secured Component Verification (SCV) - update to 1.92.0
EMC ECS - update to 3.5.0.1
IBM Cloud Transformation Advisor - update to 3.10.0
Watson Studio on Cloud Pak for Data - addressed in versions 4.8.7, 5.1.0
curl - addressed in versions 7.59.0-8.fc28, 7.61.1-4.fc29
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8

External References

Related Security Bulletins