Open redirect in libcurl and cURL - CVE-2017-1000100

 

Open redirect in libcurl and cURL - CVE-2017-1000100

Published: August 15, 2017


Vulnerability identifier: #VU7884
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-1000100
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to redirect website visitors to external websites.

The weakness exists due to incorrect validation of redirected URL. A remote attacker can redirect the target user's curl request to a TFTP URL with a long filename to cause the target user's curl application to send portions of system memory.

Successful exploitation of the vulnerability results in information disclosure.

Affected software

libcurl
cURL
Arch Linux
Debian Linux
Gentoo Linux
Amazon Linux AMI
Slackware Linux
Fedora
curl (Alpine package)
curl
Dynamic System Analysis (DSA) Preboot
Flex System EN6131 40Gb Ethernet / IB6131 40Gb Infiniband Switch Firmware
Dell EMC Unisphere Central

How to mitigate CVE-2017-1000100

Update to version 7.55.0.

curl (Alpine package) - update to 7.55.0-r0
Dynamic System Analysis (DSA) Preboot - update to dsyte2z-9.65
Flex System EN6131 40Gb Ethernet / IB6131 40Gb Infiniband Switch Firmware - update to 3.6.6000
Dell EMC Unisphere Central - update to 4.0.8.23220
curl - addressed in versions 7.51.0-9.fc25, 7.53.1-10.fc26

External References

Related Security Bulletins