Double Free in cURL - CVE-2016-8619

 

Double Free in cURL - CVE-2016-8619

Published: August 1, 2018 / Updated: August 3, 2020


Vulnerability identifier: #VU33018
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-8619
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The function `read_data()` in security.c in curl before version 7.51.0 is vulnerable to memory double free.


Affected software

cURL
Amazon Linux AMI
Arch Linux
SUSE Linux
Slackware Linux
Fedora
Opensuse
Modular Switchgear Monitoring (MSM)
curl (Alpine package)
curl
Dell EMC Unisphere Central

How to mitigate CVE-2016-8619

Install update from vendor's website.

cURL - update to 7.51.0
curl (Alpine package) - addressed in versions 7.49.1-r4, 7.51.0-r0
Dell EMC Unisphere Central - update to 4.0.8.23220
curl - addressed in versions 7.47.1-9.fc24, 7.51.0-1.fc25

External References

Related Security Bulletins