Heap out-of-bounds read in libcurl - CVE-2019-3823
Published: February 11, 2019
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information or cause the service to crash.
The vulnerability exists due to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. A remote attacker can trigger heap out-of-bounds read error and read contents of memory on the system or cause the service to crash..
Affected software
Gentoo Linux
Arch Linux
Red Hat Enterprise Linux for x86_64
Slackware Linux
Opensuse
Fedora
CM 1542-1
EMC Isilon OneFS
curl (Debian package)
curl (Alpine package)
curl
SCALANCE SC-600
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
How to mitigate CVE-2019-3823
curl (Debian package) - update to 7.52.1-5+deb9u9
curl (Alpine package) - update to 7.61.1-r2
SCALANCE SC-600 - update to 2.0
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
curl - update to 7.61.1-8.fc29
External References
Related Security Bulletins
- Multiple vulnerabilities in libcurl
- Slackware Linux update for curl
- Debian update for curl
- Arch Linux update for lib32-curl
- Arch Linux update for lib32-libcurl-compat
- Arch Linux update for lib32-libcurl-gnutls
- Arch Linux update for libcurl-gnutls
- Arch Linux update for curl
- OpenSUSE Linux update for curl
- OpenSUSE Linux update for curl
- Gentoo update for cURL
- Red Hat update for curl
- Heap out-of-bounds read in curl (Alpine package)
- Out-of-bounds Read in Siemens SCALANCE and SIMATIC NET CM 1542-1
- Multiple vulnerabilities in Dell EMC Unity Family
- Multiple vulnerabilities in Dell EMC Isilon OneFS
- Fedora 29 update for curl