Stack-based buffer overflow in cURL - CVE-2022-35260
Published: October 26, 2022
Vulnerability identifier: #VU68747
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-35260
CWE-ID: CWE-121
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error when parsing .netrc file. A local user can pass a specially crafted file to the curl, trigger a stack-based buffer overflow and perform a denial of service (DoS) attack.
Affected software
cURL
Amazon Linux AMI
PowerSC
Gentoo Linux
Oracle Solaris
macOS
Slackware Linux
Ubuntu
Fedora
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
cflinuxfs3
IBM Engineering Requirements Management DOORS Next
LANTIME Operating System Firmware (LTOS)
Splunk Universal Forwarder
Splunk Enterprise
SINEC NMS
libcurl3-gnutls (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl4 (Ubuntu package)
curl (Ubuntu package)
curl
net-misc/curl
IBM QRadar WinCollect Agent
Amazon Linux AMI
PowerSC
Gentoo Linux
Oracle Solaris
macOS
Slackware Linux
Ubuntu
Fedora
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
cflinuxfs3
IBM Engineering Requirements Management DOORS Next
LANTIME Operating System Firmware (LTOS)
Splunk Universal Forwarder
Splunk Enterprise
SINEC NMS
libcurl3-gnutls (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl4 (Ubuntu package)
curl (Ubuntu package)
curl
net-misc/curl
IBM QRadar WinCollect Agent
How to mitigate CVE-2022-35260
Install updates from vendor's website.
cURL - update to 7.86.0
cflinuxfs3 - update to 0.330.0
LANTIME Operating System Firmware (LTOS) - addressed in versions 6.24.035, 7.06.008
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
macOS - addressed in versions 12.6.3 21G419, 13.2 22D49
SINEC NMS - update to 1.0.3.1
libcurl3-gnutls (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.21, 7.68.0-1ubuntu2.14, 7.81.0-1ubuntu1.6, 7.85.0-1ubuntu0.1
libcurl3-nss (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.21, 7.68.0-1ubuntu2.14, 7.81.0-1ubuntu1.6, 7.85.0-1ubuntu0.1
libcurl4 (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.21, 7.68.0-1ubuntu2.14, 7.81.0-1ubuntu1.6, 7.85.0-1ubuntu0.1
curl (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.21, 7.68.0-1ubuntu2.14, 7.81.0-1ubuntu1.6, 7.85.0-1ubuntu0.1
curl - addressed in versions 7.79.1-7.fc35, 7.82.0-9.fc36, 7.85.0-2.fc37
net-misc/curl - update to 7.86.0
curl - update to 7.86.0
curl - update to 7.87.0-2
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
IBM QRadar WinCollect Agent - update to 10.1.1
cflinuxfs3 - update to 0.330.0
LANTIME Operating System Firmware (LTOS) - addressed in versions 6.24.035, 7.06.008
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
macOS - addressed in versions 12.6.3 21G419, 13.2 22D49
SINEC NMS - update to 1.0.3.1
libcurl3-gnutls (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.21, 7.68.0-1ubuntu2.14, 7.81.0-1ubuntu1.6, 7.85.0-1ubuntu0.1
libcurl3-nss (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.21, 7.68.0-1ubuntu2.14, 7.81.0-1ubuntu1.6, 7.85.0-1ubuntu0.1
libcurl4 (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.21, 7.68.0-1ubuntu2.14, 7.81.0-1ubuntu1.6, 7.85.0-1ubuntu0.1
curl (Ubuntu package) - addressed in versions 7.58.0-2ubuntu3.21, 7.68.0-1ubuntu2.14, 7.81.0-1ubuntu1.6, 7.85.0-1ubuntu0.1
curl - addressed in versions 7.79.1-7.fc35, 7.82.0-9.fc36, 7.85.0-2.fc37
net-misc/curl - update to 7.86.0
curl - update to 7.86.0
curl - update to 7.87.0-2
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
IBM QRadar WinCollect Agent - update to 10.1.1
External References
Related Security Bulletins
- Multiple vulnerabilities in cURL
- Ubuntu update for curl
- Slackware Linux update for curl
- Multiple vulnerabilities in cflinuxfs3
- Multiple vulnerabilities in IBM QRadar Wincollect agent
- Gentoo update for curl
- Multiple vulnerabilities in Apple macOS Monterey
- Multiple vulnerabilities in Apple macOS Ventura
- Multiple vulnerabilities in IBM PowerSC
- Multiple vulnerabilities in Oracle Solaris
- Multiple vulnerabilities in Siemens SINEC NMS
- Splunk Universal Forwarder update for third-party packages
- Multiple vulnerabilities in Dell Data Protection Central
- Splunk Enterprise update for third-party packages
- Multiple vulnerabilities in IBM Engineering Requirements Management DOORS/DWA
- Amazon Linux AMI update for curl
- Fedora 36 update for curl
- Fedora 35 update for curl
- Fedora 37 update for curl
- Meinberg LANTIME firmware update for third-party components (January 2023)