Improper Neutralization of HTTP Headers for Scripting Syntax in cURL - CVE-2020-8177
Published: June 25, 2020
Vulnerability details
The vulnerability allows a remote attacker to overwrite files on the victim's system.
The vulnerability exists due to a logical error when processing Content-Disposition: HTTP response header in curl when executed with the -J flag and -i flags in the same command line. A remote attacker can trick the victim to run a specially crafted curl command against a malicious website and overwrite files on the user's system.
Affected software
Cloud Pak for Security (CP4S)
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
CentOS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - TUS
Slackware Linux
Opensuse
openEuler
Fedora
curl (Alpine package)
curl (Red Hat package)
curl (Debian package)
curl
curl-debuginfo
curl-debugsource
curl-help
libcurl
libcurl-devel
mingw-curl
TensorFlow
Ansible Automation Platform
IBM Cloud Transformation Advisor
Red Hat OpenShift Serverless
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift Virtualization
Red Hat OpenShift Container Platform
Splunk Universal Forwarder
Splunk Enterprise
SINEC INS
Secured Component Verification (SCV)
Data Computing Appliance (DCA)
How to mitigate CVE-2020-8177
TensorFlow - update to 2.5.0
Ansible Automation Platform - update to 1.2.4
Cloud Pak for Security (CP4S) - update to 1.8.0.0
Red Hat OpenShift Serverless - update to 1.11.0
Red Hat OpenShift Container Platform - addressed in versions 4.5.20, 4.5.23
curl (Alpine package) - update to 7.71.0-r0
curl (Red Hat package) - addressed in versions 7.29.0-59.el7_9.1, 7.61.1-12.el8_2.2, 7.61.1-14.el8
curl (Debian package) - update to 7.64.0-4+deb10u2
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
SINEC INS - update to 1.0.1.1
Secured Component Verification (SCV) - update to 1.92.0
OpenShift Virtualization - update to 2.5.3
IBM Cloud Transformation Advisor - update to 3.10.0
Data Computing Appliance (DCA) - update to 4.3.0.0
curl - addressed in versions 7.66.0-2.fc31, 7.69.1-4.fc32
curl - update to 7.69.1-2
curl-debuginfo - update to 7.69.1-2
curl-debugsource - update to 7.69.1-2
curl-help - update to 7.69.1-2
libcurl - update to 7.69.1-2
libcurl-devel - update to 7.69.1-2
mingw-curl - update to 7.71.1-1.fc32
External References
Related Security Bulletins
- Security restrictions bypass in cURL
- Slackware Linux update for curl
- OpenSUSE Linux update for curl
- OpenSUSE Linux update for curl
- Gentoo update for cURL
- Amazon Linux AMI update for curl
- Improper Neutralization of HTTP Headers for Scripting Syntax in curl (Alpine package)
- Red Hat Enterprise Linux 8 update for curl
- Red Hat Enterprise Linux 7 update for curl
- CentOS 7 update for curl
- Multiple vulnerabilities in Red Hat Openshift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Container Platform
- Multiple vulnerabilities in Red Hat OpenShift Container Platform
- Red Hat Enterprise Linux 8.2 update for curl
- Multiple vulnerabilities in Red Hat OpenShift Container Storage
- Debian update for curl
- Tensorflow update for third-party components
- Multiple vulnerabilities in Siemens SINEC INS
- Multiple vulnerabilities in IBM Cloud Pak for Security
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 1.2
- Splunk Universal Forwarder update for third-party packages
- Splunk Enterprise update for third-party packages
- openEuler 20.03 LTS update for curl-7.69.1-1
- Multiple vulnerabilities in Dell Secured Component Verification (SCV)
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in OpenShift Virtualization 2.5
- Fedora 31 update for curl
- Fedora 32 update for curl
- Fedora 32 update for mingw-curl