Stack-based buffer overflow in cURL - CVE-2022-35260

 

Stack-based buffer overflow in cURL - CVE-2022-35260

Published: October 26, 2022


Vulnerability identifier: #VU68747
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-35260
CWE-ID: CWE-121
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error when parsing .netrc file. A local user can pass a specially crafted file to the curl, trigger a stack-based buffer overflow and perform a denial of service (DoS) attack.


Affected software

cURL
Amazon Linux AMI
PowerSC
Gentoo Linux
Oracle Solaris
macOS
Slackware Linux
Ubuntu
Fedora
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
cflinuxfs3
IBM Engineering Requirements Management DOORS Next
LANTIME Operating System Firmware (LTOS)
Splunk Universal Forwarder
Splunk Enterprise
SINEC NMS
libcurl3-gnutls (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl4 (Ubuntu package)
curl (Ubuntu package)
curl
net-misc/curl
IBM QRadar WinCollect Agent

How to mitigate CVE-2022-35260

Install updates from vendor's website.

cURL - update to 7.86.0
cflinuxfs3 - update to 0.330.0
LANTIME Operating System Firmware (LTOS) - addressed in versions 6.24.035, 7.06.008
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
macOS - addressed in versions 12.6.3 21G419, 13.2 22D49
SINEC NMS - update to 1.0.3.1
libcurl3-gnutls (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.21, 7.68.0-1ubuntu2.14, 7.81.0-1ubuntu1.6, 7.85.0-1ubuntu0.1
libcurl3-nss (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.21, 7.68.0-1ubuntu2.14, 7.81.0-1ubuntu1.6, 7.85.0-1ubuntu0.1
libcurl4 (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.21, 7.68.0-1ubuntu2.14, 7.81.0-1ubuntu1.6, 7.85.0-1ubuntu0.1
curl (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.21, 7.68.0-1ubuntu2.14, 7.81.0-1ubuntu1.6, 7.85.0-1ubuntu0.1
curl - addressed in versions 7.79.1-7.fc35, 7.82.0-9.fc36, 7.85.0-2.fc37
net-misc/curl - update to 7.86.0
curl - update to 7.86.0
curl - update to 7.87.0-2
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
IBM QRadar WinCollect Agent - update to 10.1.1

External References

Related Security Bulletins