Out-of-bounds read in cURL - CVE-2016-8620

 

Out-of-bounds read in cURL - CVE-2016-8620

Published: August 1, 2018 / Updated: August 3, 2020


Vulnerability identifier: #VU33019
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-8620
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read via user controlled input.


Affected software

cURL
Amazon Linux AMI
Arch Linux
SUSE Linux
Slackware Linux
Fedora
Opensuse
curl (Alpine package)
curl
Dell EMC Unisphere Central

How to mitigate CVE-2016-8620

Install update from vendor's website.

cURL - update to 7.51.0
curl (Alpine package) - addressed in versions 7.49.1-r4, 7.51.0-r0
Dell EMC Unisphere Central - update to 4.0.8.23220
curl - addressed in versions 7.47.1-9.fc24, 7.51.0-1.fc25

External References

Related Security Bulletins