Use-after-free in cURL - CVE-2016-8623

 

Use-after-free in cURL - CVE-2016-8623

Published: August 1, 2018 / Updated: August 3, 2020


Vulnerability identifier: #VU33013
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-8623
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

A flaw was found in curl before version 7.51.0. The way curl handles cookies permits other threads to trigger a use-after-free leading to information disclosure.


Affected software

cURL
Amazon Linux AMI
Arch Linux
SUSE Linux
Slackware Linux
Fedora
Opensuse
curl (Alpine package)
curl
Dell EMC Unisphere Central

How to mitigate CVE-2016-8623

Install update from vendor's website.

cURL - update to 7.51.0
curl (Alpine package) - addressed in versions 7.49.1-r4, 7.51.0-r0
Dell EMC Unisphere Central - update to 4.0.8.23220
curl - addressed in versions 7.47.1-9.fc24, 7.51.0-1.fc25

External References

Related Security Bulletins