Double Free in cURL - CVE-2019-5481

 

Double Free in cURL - CVE-2019-5481

Published: September 11, 2019


Vulnerability identifier: #VU21058
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-5481
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform denial of service (DoS) attack.

The vulnerability exists due to a boundary error when processing very large blocks during Kerberos FTP data transfer. A remote attacker that controls malicious FTP server can send large blocks of data to the curl client, trigger a double-free error and crash the application.


Affected software

cURL
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Slackware Linux
Opensuse
Fedora
curl (Ubuntu package)
curl (Debian package)
curl (Red Hat package)
gnurl (Alpine package)
curl
IBM Cloud Transformation Advisor
Watson Studio on Cloud Pak for Data

How to mitigate CVE-2019-5481

Install updates from vendor's website.

cURL - update to 7.66.0
curl (Ubuntu package) - addressed in versions 7.47.0-1ubuntu2.14, 7.58.0-2ubuntu3.8, 7.64.0-2ubuntu1.2
curl (Debian package) - update to 7.52.1-5+deb9u10
curl (Red Hat package) - update to 7.61.1-12.el8
gnurl (Alpine package) - update to 7.67.0-r0
IBM Cloud Transformation Advisor - update to 3.10.0
Watson Studio on Cloud Pak for Data - addressed in versions 4.8.7, 5.1.0
curl - addressed in versions 7.61.1-12.fc29, 7.65.3-4.fc30, 7.66.0-1.fc31

External References

Related Security Bulletins