Infinite loop in cURL - CVE-2022-27781

 

Infinite loop in cURL - CVE-2022-27781

Published: May 11, 2022


Vulnerability identifier: #VU63008
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-27781
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop when handling requests with the CURLOPT_CERTINFO option. A remote attacker can consume all available system resources and cause denial of service conditions.


Affected software

cURL
Amazon Linux AMI
Gentoo Linux
PowerSC
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
Slackware Linux
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
openEuler
My Cloud OS 5
My Cloud PR2100
My Cloud PR4100
My Cloud EX4100
My Cloud EX2 Ultra
My Cloud Mirror G2
My Cloud DL2100
My Cloud DL4100
My Cloud EX2100
WD Cloud
My Cloud
cflinuxfs3
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
EMC ECS
Platform Automation Toolkit
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Watson Studio on Cloud Pak for Data
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Virtual Environments: Data Protection for VMware
IBM Engineering Requirements Management DOORS Next
Data Lakehouse
Dell Secure Connect Gateway
Isolation Segment
VMware Tanzu Application Service for VMs
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Spectrum Protect Plus
Dell EMC NetWorker vProxy
Splunk Enterprise
Splunk Universal Forwarder
Cisco Jabber
Cisco Webex Meetings
VMware Horizon Client
HPE Moonshot 1500 Chassis Manager
RUGGEDCOM ROX MX5000
RUGGEDCOM ROX RX1524
RUGGEDCOM ROX MX5000RE
RUGGEDCOM ROX RX1400
RUGGEDCOM ROX RX1536
RUGGEDCOM ROX RX5000
RUGGEDCOM ROX RX1500
RUGGEDCOM ROX RX1501
RUGGEDCOM ROX RX1510
RUGGEDCOM ROX RX1511
RUGGEDCOM ROX RX1512
PowerScale OneFS
Dell EMC Storage Monitoring and Reporting (SMR)
Dell EMC VxRail Appliance
libcurl3 (Ubuntu package)
curl (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
libcurl4 (Ubuntu package)
libcurl4-debuginfo
libcurl4-debuginfo-32bit
libcurl4
libcurl4-32bit
curl-debugsource
curl
curl-debuginfo
libcurl-devel
libcurl4-32bit-debuginfo
libcurl-devel-32bit
curl-help
libcurl
curl (Debian package)
net-misc/curl

How to mitigate CVE-2022-27781

Install updates from vendor's website.

cURL - update to 7.83.1
cflinuxfs3 - update to 0.296.0
Data Lakehouse - update to 1.1.0.0
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Dell EMC NetWorker vProxy - update to 4.3.0-32
Dell Secure Connect Gateway - update to 5.12.00.10
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
Isolation Segment - addressed in versions 2.7.45, 2.10.25, 2.11.14, 2.12.8
VMware Tanzu Application Service for VMs - addressed in versions 2.7.50, 2.10.32, 2.11.20, 2.12.13, 2.13.5
RUGGEDCOM ROX MX5000 - update to 2.16.0
RUGGEDCOM ROX RX1524 - update to 2.16.0
RUGGEDCOM ROX MX5000RE - update to 2.16.0
RUGGEDCOM ROX RX1400 - update to 2.16.0
RUGGEDCOM ROX RX1536 - update to 2.16.0
RUGGEDCOM ROX RX5000 - update to 2.16.0
RUGGEDCOM ROX RX1500 - update to 2.16.0
RUGGEDCOM ROX RX1501 - update to 2.16.0
RUGGEDCOM ROX RX1510 - update to 2.16.0
RUGGEDCOM ROX RX1511 - update to 2.16.0
RUGGEDCOM ROX RX1512 - update to 2.16.0
EMC ECS - update to 3.8.0.2
IBM Cloud Transformation Advisor - update to 3.10.0
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
Platform Automation Toolkit - addressed in versions 4.4.29, 5.0.22
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.0
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
DB2 on Cloud Pak for Data - update to 4.8.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.4
Watson Studio on Cloud Pak for Data - update to 5.0.3
My Cloud OS 5 - update to 5.25.124
Dell EMC VxRail Appliance - addressed in versions 7.0.372, 8.0.000
libcurl3 (Ubuntu package) - update to 7.47.01ubuntu2.19+esm4
curl (Ubuntu package) - addressed in versions 7.47.01ubuntu2.19+esm4, 7.58.0-2ubuntu3.18, 7.68.0-1ubuntu2.11, 7.74.0-1.3ubuntu2.2, 7.81.0-1ubuntu1.2
libcurl3-nss (Ubuntu package) - addressed in versions 7.47.01ubuntu2.19+esm4, 7.58.0-2ubuntu3.18, 7.68.0-1ubuntu2.11, 7.74.0-1.3ubuntu2.2, 7.81.0-1ubuntu1.2
libcurl3-gnutls (Ubuntu package) - addressed in versions 7.47.01ubuntu2.19+esm4, 7.58.0-2ubuntu3.18, 7.68.0-1ubuntu2.11, 7.74.0-1.3ubuntu2.2, 7.81.0-1ubuntu1.2
libcurl4 (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.18, 7.68.0-1ubuntu2.11, 7.74.0-1.3ubuntu2.2, 7.81.0-1ubuntu1.2
libcurl4-debuginfo - addressed in versions 7.60.0-4.38.1, 7.60.0-11.40.2, 7.60.0-150000.33.1, 7.66.0-150200.4.33.1
libcurl4-debuginfo-32bit - addressed in versions 7.60.0-4.38.1, 7.60.0-11.40.2
libcurl4 - addressed in versions 7.60.0-4.38.1, 7.60.0-11.40.2, 7.60.0-150000.33.1, 7.66.0-150200.4.33.1
libcurl4-32bit - addressed in versions 7.60.0-4.38.1, 7.60.0-11.40.2, 7.60.0-150000.33.1, 7.66.0-150200.4.33.1
curl-debugsource - addressed in versions 7.60.0-4.38.1, 7.60.0-11.40.2, 7.60.0-150000.33.1, 7.66.0-150200.4.33.1
curl - addressed in versions 7.60.0-4.38.1, 7.60.0-11.40.2, 7.60.0-150000.33.1, 7.66.0-150200.4.33.1
curl-debuginfo - addressed in versions 7.60.0-4.38.1, 7.60.0-11.40.2, 7.60.0-150000.33.1, 7.66.0-150200.4.33.1
libcurl-devel - addressed in versions 7.60.0-11.40.2, 7.60.0-150000.33.1, 7.66.0-150200.4.33.1
libcurl4-32bit-debuginfo - addressed in versions 7.60.0-150000.33.1, 7.66.0-150200.4.33.1
curl - addressed in versions 7.61.1-12.101, 7.87.0-2
libcurl-devel-32bit - update to 7.66.0-150200.4.33.1
curl-help - update to 7.71.1-14
libcurl-devel - update to 7.71.1-14
libcurl - update to 7.71.1-14
curl-debuginfo - update to 7.71.1-14
curl-debugsource - update to 7.71.1-14
curl - update to 7.71.1-14
curl (Debian package) - update to 7.74.0-1.3+deb11u2
net-misc/curl - update to 7.86.0
Storage Protect Client - update to 8.1.22.0
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.22.0
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.22.0
PowerScale OneFS - addressed in versions 9.1.0.26, 9.2.1.19, 9.4.0.10
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
IBM Spectrum Protect Plus - update to 10.1.12

External References

Related Security Bulletins