Use-after-free error in libcurl - CVE-2018-16840

 

Use-after-free error in libcurl - CVE-2018-16840

Published: November 1, 2018 / Updated: November 1, 2018


Vulnerability identifier: #VU15672
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-16840
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists due to use-after-free error in closing an easy handle in the 'Curl_close()' function. A remote unauthenticated attacker can specially crafted data, trigger memory corruption and cause the service to crash.


Affected software

libcurl
Arch Linux
Amazon Linux AMI
Gentoo Linux
Slackware Linux
Opensuse
Fedora
curl (Alpine package)
curl
Dynamic System Analysis (DSA) Preboot
Secured Component Verification (SCV)
Watson Studio on Cloud Pak for Data
Flex System Chassis Management Module (CMM)
IBM Cloud Transformation Advisor
Dell EMC Unisphere Central
Dell EMC Data Protection Search

How to mitigate CVE-2018-16840

Update to version 7.62.0.

libcurl - update to 7.62.0
curl (Alpine package) - addressed in versions 7.61.1-r1, 7.62.0-r0
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
Secured Component Verification (SCV) - update to 1.92.0
Flex System Chassis Management Module (CMM) - update to 2pet18a-2.5.14a
IBM Cloud Transformation Advisor - update to 3.10.0
Dell EMC Unisphere Central - update to 4.0.8.23220
Watson Studio on Cloud Pak for Data - addressed in versions 4.8.7, 5.1.0
curl - addressed in versions 7.59.0-8.fc28, 7.61.1-4.fc29
Dell EMC Data Protection Search - update to 18.2.1

External References

Related Security Bulletins