Out-of-bounds write in cURL - CVE-2016-8617
Published: August 1, 2018 / Updated: August 3, 2020
Vulnerability identifier: #VU33012
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-8617
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local authenticated user to execute arbitrary code.
The base64 encode function in curl before version 7.51.0 is prone to a buffer being under allocated in 32bit systems if it receives at least 1Gb as input via `CURLOPT_USERNAME`.
Affected software
cURL
Amazon Linux AMI
Arch Linux
SUSE Linux
Slackware Linux
Fedora
Opensuse
Modular Switchgear Monitoring (MSM)
curl (Alpine package)
curl
Dell EMC Unisphere Central
Amazon Linux AMI
Arch Linux
SUSE Linux
Slackware Linux
Fedora
Opensuse
Modular Switchgear Monitoring (MSM)
curl (Alpine package)
curl
Dell EMC Unisphere Central
How to mitigate CVE-2016-8617
Install update from vendor's website.
cURL - update to 7.51.0
curl (Alpine package) - addressed in versions 7.49.1-r4, 7.51.0-r0
Dell EMC Unisphere Central - update to 4.0.8.23220
curl - addressed in versions 7.47.1-9.fc24, 7.51.0-1.fc25
curl (Alpine package) - addressed in versions 7.49.1-r4, 7.51.0-r0
Dell EMC Unisphere Central - update to 4.0.8.23220
curl - addressed in versions 7.47.1-9.fc24, 7.51.0-1.fc25
External References
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.securityfocus.com/bid/94097
- http://www.securitytracker.com/id/1037192
- https://access.redhat.com/errata/RHSA-2018:2486
- https://access.redhat.com/errata/RHSA-2018:3558
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8617
- https://curl.haxx.se/CVE-2016-8617.patch
- https://curl.haxx.se/docs/adv_20161102C.html
- https://security.gentoo.org/glsa/201701-47
- https://www.tenable.com/security/tns-2016-21
Related Security Bulletins
- Out-of-bounds write in curl.haxx.se cURL
- OpenSUSE Linux update for curl
- SUSE Linux update for curl
- SUSE Linux update for curl
- Out-of-bounds write in curl (Alpine package)
- Arch Linux update for lib32-libcurl-gnutls
- Arch Linux update for libcurl-gnutls
- Arch Linux update for libcurl-compat
- Arch Linux update for curl
- Arch Linux update for lib32-libcurl-compat
- Arch Linux update for lib32-curl
- Amazon Linux AMI update for curl
- Slackware Linux update for curl
- Multiple vulnerabilities in Hitachi Energy MSM Product
- Multiple vulnerabilities in Dell EMC Unisphere Central
- Fedora 24 update for curl
- Fedora 25 update for curl