Improper Neutralization of HTTP Headers for Scripting Syntax in cURL - CVE-2020-8177

 

Improper Neutralization of HTTP Headers for Scripting Syntax in cURL - CVE-2020-8177

Published: June 25, 2020


Vulnerability identifier: #VU29290
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8177
CWE-ID: CWE-644
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to overwrite files on the victim's system.

The vulnerability exists due to a logical error when processing Content-Disposition: HTTP response header in curl when executed with the -J flag and -i flags in the same command line. A remote attacker can trick the victim to run a specially crafted curl command against a malicious website and overwrite files on the user's system.


Affected software

cURL
Cloud Pak for Security (CP4S)
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
CentOS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - TUS
Slackware Linux
Opensuse
openEuler
Fedora
curl (Alpine package)
curl (Red Hat package)
curl (Debian package)
curl
curl-debuginfo
curl-debugsource
curl-help
libcurl
libcurl-devel
mingw-curl
TensorFlow
Ansible Automation Platform
IBM Cloud Transformation Advisor
Red Hat OpenShift Serverless
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift Virtualization
Red Hat OpenShift Container Platform
Splunk Universal Forwarder
Splunk Enterprise
SINEC INS
Secured Component Verification (SCV)
Data Computing Appliance (DCA)

How to mitigate CVE-2020-8177

Install updates from vendor's website.

cURL - update to 7.71.0
TensorFlow - update to 2.5.0
Ansible Automation Platform - update to 1.2.4
Cloud Pak for Security (CP4S) - update to 1.8.0.0
Red Hat OpenShift Serverless - update to 1.11.0
Red Hat OpenShift Container Platform - addressed in versions 4.5.20, 4.5.23
curl (Alpine package) - update to 7.71.0-r0
curl (Red Hat package) - addressed in versions 7.29.0-59.el7_9.1, 7.61.1-12.el8_2.2, 7.61.1-14.el8
curl (Debian package) - update to 7.64.0-4+deb10u2
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
SINEC INS - update to 1.0.1.1
Secured Component Verification (SCV) - update to 1.92.0
OpenShift Virtualization - update to 2.5.3
IBM Cloud Transformation Advisor - update to 3.10.0
Data Computing Appliance (DCA) - update to 4.3.0.0
curl - addressed in versions 7.66.0-2.fc31, 7.69.1-4.fc32
curl - update to 7.69.1-2
curl-debuginfo - update to 7.69.1-2
curl-debugsource - update to 7.69.1-2
curl-help - update to 7.69.1-2
libcurl - update to 7.69.1-2
libcurl-devel - update to 7.69.1-2
mingw-curl - update to 7.71.1-1.fc32

External References

Related Security Bulletins