Resource exhaustion in cURL - CVE-2023-38039

 

Resource exhaustion in cURL - CVE-2023-38039

Published: September 13, 2023


Vulnerability identifier: #VU80732
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-38039
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not limit the size of received headers from a single request that are stored for future reference. A remote attacker can send overly large HTTP responses to the application and consume all memory resources.


Affected software

cURL
Oracle Database Server
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
PowerSC
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
macOS
Slackware Linux
Basesystem Module
openSUSE Leap
Anolis OS
Ubuntu
Fedora
Splunk User Behavior Analytics (UBA)
IBM QRadar WinCollect Agent
EasyApache
App Connect Enterprise Certified Container
Dell Secure Connect Gateway
IBM Sterling Secure Proxy
IBM Safer Payments
IBM MQ
IBM Rational ClearCase
IBM Engineering Requirements Management DOORS Next
ObjectScale
Index Engines CyberSense
Dell Data Protection Central
Robotic Process Automation for Cloud Pak
IBM App Connect Enterprise
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
curl
libcurl3-gnutls (Ubuntu package)
curl (Ubuntu package)
libcurl4 (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl-devel
curl-debugsource
curl-debuginfo
libcurl4-debuginfo
libcurl4
libcurl4-debuginfo-32bit
libcurl4-32bit
libcurl4-64bit-debuginfo
libcurl-devel-64bit
libcurl4-64bit
libcurl4-32bit-debuginfo
libcurl-devel-32bit
net-misc/curl
libcurl-minimal
curl-doc
libcurl
curl-minimal
jbcs-httpd24-curl (Red Hat package)
JBoss Core Services
RecoverPoint for VMs
Dell EMC VxRail Appliance
Dell EMC NetWorker vProxy

How to mitigate CVE-2023-38039

Install updates from vendor's website.

cURL - update to 8.3.0
Oracle Database Server - update to 19.3
Splunk User Behavior Analytics (UBA) - update to 5.4.3
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
IBM QRadar WinCollect Agent - update to 10.1.8
macOS - addressed in versions 12.7.3 21H1015, 13.6.4 22G513, 14.2 23C64
IBM App Connect Enterprise - update to 12.0.10.1
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-34.el7jbcs, 0.4.10-34.el8jbcs
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-19.el7jbcs, 1.0.0-19.el8jbcs
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.19-7.el7jbcs, 1.3.19-7.el8jbcs
ObjectScale - update to 1.4.0
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-103.el7jbcs, 1.6.1-103.el8jbcs
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-32.el7jbcs, 1.15.19-32.el8jbcs
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.24-2.el7jbcs, 2.4.24-2.el8jbcs
JBoss Core Services - update to 2.4.57 SP2
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.57-7.el7jbcs, 2.4.57-7.el8jbcs
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-32.el7jbcs, 2.9.3-32.el8jbcs
EasyApache - update to 4 2023-9-20
App Connect Enterprise Certified Container - addressed in versions 5.0.13, 11.0.0
Dell Secure Connect Gateway - update to 5.20.00.10
RecoverPoint for VMs - update to 6.0.SP1.P1
IBM Sterling Secure Proxy - addressed in versions 6.0.3 iFix 11, 6.1.0 iFix 03
IBM Safer Payments - addressed in versions 6.4.2.06, 6.5.0.04, 6.6.0.02
curl - addressed in versions 7.85.0-11.fc37, 8.0.1-4.fc38, 8.2.1-2.fc39
libcurl3-gnutls (Ubuntu package) - update to 7.88.1-8ubuntu2.2
curl (Ubuntu package) - update to 7.88.1-8ubuntu2.2
libcurl4 (Ubuntu package) - update to 7.88.1-8ubuntu2.2
libcurl3-nss (Ubuntu package) - update to 7.88.1-8ubuntu2.2
libcurl-devel - addressed in versions 8.0.1-11.71.1, 8.0.1-150400.5.29.1
curl-debugsource - addressed in versions 8.0.1-11.71.1, 8.0.1-150400.5.29.1
curl-debuginfo - addressed in versions 8.0.1-11.71.1, 8.0.1-150400.5.29.1
curl - addressed in versions 8.0.1-11.71.1, 8.0.1-150400.5.29.1
libcurl4-debuginfo - addressed in versions 8.0.1-11.71.1, 8.0.1-150400.5.29.1
libcurl4 - addressed in versions 8.0.1-11.71.1, 8.0.1-150400.5.29.1
libcurl4-debuginfo-32bit - update to 8.0.1-11.71.1
libcurl4-32bit - addressed in versions 8.0.1-11.71.1, 8.0.1-150400.5.29.1
libcurl4-64bit-debuginfo - update to 8.0.1-150400.5.29.1
libcurl-devel-64bit - update to 8.0.1-150400.5.29.1
libcurl4-64bit - update to 8.0.1-150400.5.29.1
libcurl4-32bit-debuginfo - update to 8.0.1-150400.5.29.1
libcurl-devel-32bit - update to 8.0.1-150400.5.29.1
Dell EMC VxRail Appliance - update to 8.0.120
curl - update to 8.3.0
net-misc/curl - update to 8.3.0-r2
curl - update to 8.3.0-1
Index Engines CyberSense - update to 8.4
libcurl-minimal - update to 8.4.0-1
curl-doc - update to 8.4.0-1
libcurl-devel - update to 8.4.0-1
libcurl - update to 8.4.0-1
curl-minimal - update to 8.4.0-1
curl - update to 8.4.0-1
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.4.0-2.el7jbcs, 8.4.0-2.el8jbcs
IBM MQ - addressed in versions 9.0.0.21, 9.1.0.18, 9.2.0.20, 9.3.0.11, 9.3.4
IBM Rational ClearCase - addressed in versions 9.1.0.6, 10.0.1.1
Dell EMC NetWorker vProxy - addressed in versions 19.9.0.4, 19.10
Dell Data Protection Central - update to 19.10.0-4
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.11, 23.0.12

External References

Related Security Bulletins