Heap-based buffer overflow in cURL - CVE-2023-38545

 

Heap-based buffer overflow in cURL - CVE-2023-38545

Published: October 11, 2023 / Updated: February 21, 2025


Vulnerability identifier: #VU81865
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-38545
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in the SOCKS5 proxy handshake. A remote attacker can trick the victim to visit a malicious website, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system but requires that SOCKS5 proxy is used and that SOCKS5 handshake is slow (e.g. under heavy load or DoS attack).


Affected software

cURL
My Cloud Home Duo
My Cloud Home
Service Interconnect
Data Lakehouse
Red Hat OpenShift Builds
Red Hat OpenShift Kernel Module Management
cert-manager Operator for Red Hat OpenShift
Migration Toolkit for Virtualization
Splunk User Behavior Analytics (UBA)
OpenShift Logging
Red Hat Migration Toolkit for Applications
Red Hat Satellite
Oracle HTTP Server
Red Hat OpenStack
IBM Cloud Pak for Business Automation
IBM MQ Operator
IBM Cloud Transformation Advisor
IBM Cloud Object Storage Systems
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
EasyApache
Dell Secure Connect Gateway
IBM Safer Payments
IBM Rational ClearCase
IBM QRadar WinCollect Agent
EMC NetWorker Server
IBM Automation Decision Services
IBM Observability with Instana
Oracle Linux
Gentoo Linux
Amazon Linux AMI
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
PowerSC
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Red Hat Enterprise Linux Server - Extended Life Cycle Support
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
FortiOS
IBM AIX
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
macOS
Slackware Linux
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Fedora
My Cloud OS 5
Junos OS
Chrome OS
RUGGEDCOM APE1808
Dell EMC VxRail Appliance
Oracle Database Server
MySQL Server
Oracle Essbase
My Cloud (P/N: WDBCTLxxxxxx-10)
My Cloud DL4100
My Cloud PR2100
My Cloud PR4100
My Cloud EX2 Ultra
My Cloud EX4100
My Cloud Mirror Gen 2
My Cloud EX2100
OSS Network Utilities
Red Hat OpenShift Container Platform
VMware Horizon Client
Telemetry Dashboard
Liquidware
Oracle Business Intelligence Enterprise Edition
IBM Engineering Requirements Management DOORS Next
Citrix Workspace App
Webex App VDI
Storage Copy Data Management
Oxygen Feedback
Storage Resource Manager
Watson Studio on Cloud Pak for Data
Storage Ceph
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for VMware
IBM supplied MQ Advanced container images
Storage Protect Plus Server
Network Observability plugin for the Openshift Console
IBM Cloud Pak System
FactoryTalk Activation Manager
OpenShift Virtualization
OpenShift Container Platform for Windows Containers
OpenShift Data Foundation (formerly OpenShift Container Storage)
SecurityCenter
MySQL Cluster
PeopleSoft Enterprise PeopleTools
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
rubygem-foreman_scap_client (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
satellite-convert2rhel-toolkit (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
rubygem-grpc (Red Hat package)
mosquitto (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
python-pulp-container (Red Hat package)
foreman-installer (Red Hat package)
foreman (Red Hat package)
rubygem-google-protobuf (Red Hat package)
candlepin (Red Hat package)
rubygem-katello (Red Hat package)
rubygem-puma (Red Hat package)
rubygem-sidekiq (Red Hat package)
satellite (Red Hat package)
rubygem-kafo (Red Hat package)
puppetserver (Red Hat package)
puppet-agent (Red Hat package)
libcurl3-nss (Ubuntu package)
libcurl4 (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
curl (Ubuntu package)
curl-debuginfo
curl-help
curl-debugsource
libcurl-devel
libcurl
curl
curl (Debian package)
curl (Red Hat package)
libcurl4
libcurl4-32bit
libcurl4-debuginfo
libcurl4-debuginfo-32bit
libcurl-devel-32bit
libcurl4-32bit-debuginfo
libcurl-devel-64bit
libcurl4-64bit-debuginfo
libcurl4-64bit
mysql-server-8.0 (Ubuntu package)
mysql-debugsource
mysql
mysql-libs
mysql-server
mysql-common
mysql-config
mysql-debuginfo
mysql-devel
mysql-errmsg
mysql-test
mysql-help
net-misc/curl
curl-doc
libcurl-minimal
curl-minimal
jbcs-httpd24-curl (Red Hat package)
rubygem-foreman_bootdisk (Red Hat package)
IBM App Connect Enterprise
Cisco Jabber
Cisco Webex Meetings
QuTS hero
JBoss Core Services
Dell EMC Storage Monitoring and Reporting (SMR)
QNAP QTS
Red Hat Ceph Storage
RecoverPoint for VMs

How to mitigate CVE-2023-38545

Install updates from vendor's website.

cURL - update to 8.4.0
OSS Network Utilities - update to T1204L01^AAI
Data Lakehouse - update to 1.1.0.0
Red Hat OpenShift Builds - update to 1.0.1
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Red Hat OpenShift Kernel Module Management - update to 1.1.2
Network Observability plugin for the Openshift Console - update to 1.5.0
cert-manager Operator for Red Hat OpenShift - addressed in versions 1.11.5, 1.12.1
IBM Cloud Pak System - update to 2.3.5.1
Migration Toolkit for Virtualization - addressed in versions 2.4.3, 2.5.2
FactoryTalk Activation Manager - update to 5.01
Red Hat OpenShift Container Platform - addressed in versions 4.12.40, 4.13.19, 4.14.0
OpenShift Virtualization - addressed in versions 4.13.5, 4.13.6, 4.14.1
Splunk User Behavior Analytics (UBA) - update to 5.4.3
OpenShift Logging - update to 5.8.1
SecurityCenter - update to SC-202310.1
Red Hat Migration Toolkit for Applications - addressed in versions 6.2, 6.2.1
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
Red Hat Satellite - update to 6.14.2
FortiOS - addressed in versions 7.2.7, 7.4.2
MySQL Cluster - update to 8.0.35
OpenShift Container Platform for Windows Containers - addressed in versions 9.0.1, 10.15.0
My Cloud Home Duo - update to 9.7.0-104
My Cloud Home - update to 9.7.0-104
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
macOS - addressed in versions 12.7.3 21H1015, 13.6.4 22G513, 14.2 23C64
IBM App Connect Enterprise - update to 12.0.10.1
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
Red Hat OpenStack - update to 17.1.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.26, 23.0.1.4
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
QuTS hero - update to h5.1.7.2770 build 20240520
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-34.el7jbcs, 0.4.10-34.el8jbcs
rubygem-foreman_scap_client (Red Hat package) - addressed in versions 0.5.2-1.el6sat, 0.5.2-1.el7sat, 0.5.2-1.el8sat, 0.5.2-1.el9sat
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-19.el7jbcs, 1.0.0-19.el8jbcs
satellite-convert2rhel-toolkit (Red Hat package) - update to 1.0.1-1.el8sat
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.19-7.el7jbcs, 1.3.19-7.el8jbcs
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-103.el7jbcs, 1.6.1-103.el8jbcs
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-32.el7jbcs, 1.15.19-32.el8jbcs
rubygem-grpc (Red Hat package) - update to 1.58.0-1.el8sat
IBM MQ Operator - addressed in versions 2.0.16, 2.4.4
mosquitto (Red Hat package) - update to 2.0.17-1.el8sat
Storage Copy Data Management - update to 2.2.24.0
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.24-2.el7jbcs, 2.4.24-2.el8jbcs
JBoss Core Services - update to 2.4.57 SP2
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.57-7.el7jbcs, 2.4.57-7.el8jbcs
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-32.el7jbcs, 2.9.3-32.el8jbcs
python-pulp-container (Red Hat package) - update to 2.14.11-1.el8pc
foreman-installer (Red Hat package) - update to 3.7.0.7-1.el8sat
foreman (Red Hat package) - update to 3.7.0.11-2.el8sat
IBM Cloud Transformation Advisor - update to 3.10.0
IBM Cloud Object Storage Systems - addressed in versions 3.17.0.128, 3.17.5.100
rubygem-google-protobuf (Red Hat package) - update to 3.24.3-1.el8sat
Oxygen Feedback - update to 4.0 2023110114
candlepin (Red Hat package) - update to 4.3.11-1.el8sat
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.4
rubygem-katello (Red Hat package) - update to 4.9.0.21-1.el8sat
Storage Resource Manager - update to 4.10.0.3
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.3
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.14.0
EasyApache - update to 4 2023-10-12
Watson Studio on Cloud Pak for Data - update to 5.0.3
QNAP QTS - update to 5.1.7.2770 20240520
Dell Secure Connect Gateway - addressed in versions 5.20.00.10, 5.28.00.14
My Cloud OS 5 - update to 5.30.103
RecoverPoint for VMs - update to 6.0.SP1.P1
Red Hat Ceph Storage - update to 6.1
Storage Ceph - update to 6.1z3
rubygem-puma (Red Hat package) - update to 6.3.1-1.el8sat
IBM Safer Payments - addressed in versions 6.4.2.06, 6.5.0.04, 6.6.0.02
rubygem-sidekiq (Red Hat package) - update to 6.5.12-1.el8sat
satellite (Red Hat package) - update to 6.14.2-1.el8sat
rubygem-kafo (Red Hat package) - update to 7.2.0-1.el8sat
puppetserver (Red Hat package) - update to 7.14.0-1.el8sat
puppet-agent (Red Hat package) - addressed in versions 7.27.0-1.el6sat, 7.27.0-1.el7sat, 7.27.0-1.el8sat, 7.27.0-1.el9sat
libcurl3-nss (Ubuntu package) - addressed in versions 7.68.0-1ubuntu2.20, 7.81.0-1ubuntu1.14, 7.88.1-8ubuntu2.3, 8.2.1-1ubuntu3.1
libcurl4 (Ubuntu package) - addressed in versions 7.68.0-1ubuntu2.20, 7.81.0-1ubuntu1.14, 7.88.1-8ubuntu2.3, 8.2.1-1ubuntu3.1
libcurl3-gnutls (Ubuntu package) - addressed in versions 7.68.0-1ubuntu2.20, 7.81.0-1ubuntu1.14, 7.88.1-8ubuntu2.3, 8.2.1-1ubuntu3.1
curl (Ubuntu package) - addressed in versions 7.68.0-1ubuntu2.20, 7.81.0-1ubuntu1.14, 7.88.1-8ubuntu2.3, 8.2.1-1ubuntu3.1
curl-debuginfo - update to 7.71.1-31
curl-help - update to 7.71.1-31
curl-debugsource - update to 7.71.1-31
libcurl-devel - update to 7.71.1-31
libcurl - update to 7.71.1-31
curl - update to 7.71.1-31
curl (Debian package) - addressed in versions 7.74.0-1.3+deb11u10, 7.88.1-10+deb12u4
curl (Red Hat package) - addressed in versions 7.76.1-14.el9_0.9, 7.76.1-23.el9_2.4, 7.76.1-26.el9_3.2
curl - addressed in versions 7.85.0-12.fc37, 8.0.1-5.fc38, 8.2.1-3.fc39
curl-debugsource - addressed in versions 8.0.1-11.74.1, 8.0.1-150400.5.32.1
libcurl4 - addressed in versions 8.0.1-11.74.1, 8.0.1-150400.5.32.1
libcurl4-32bit - addressed in versions 8.0.1-11.74.1, 8.0.1-150400.5.32.1
libcurl4-debuginfo - addressed in versions 8.0.1-11.74.1, 8.0.1-150400.5.32.1
curl - addressed in versions 8.0.1-11.74.1, 8.0.1-150400.5.32.1
libcurl-devel - addressed in versions 8.0.1-11.74.1, 8.0.1-150400.5.32.1
curl-debuginfo - addressed in versions 8.0.1-11.74.1, 8.0.1-150400.5.32.1
libcurl4-debuginfo-32bit - update to 8.0.1-11.74.1
libcurl-devel-32bit - update to 8.0.1-150400.5.32.1
libcurl4-32bit-debuginfo - update to 8.0.1-150400.5.32.1
libcurl-devel-64bit - update to 8.0.1-150400.5.32.1
libcurl4-64bit-debuginfo - update to 8.0.1-150400.5.32.1
libcurl4-64bit - update to 8.0.1-150400.5.32.1
mysql-server-8.0 (Ubuntu package) - addressed in versions 8.0.35-0ubuntu0.20.04.1, 8.0.35-0ubuntu0.22.04.1, 8.0.35-0ubuntu0.23.04.1, 8.0.35-0ubuntu0.23.10.1
mysql-debugsource - update to 8.0.38-1
mysql - update to 8.0.38-1
mysql-libs - update to 8.0.38-1
mysql-server - update to 8.0.38-1
mysql-common - update to 8.0.38-1
mysql-config - update to 8.0.38-1
mysql-debuginfo - update to 8.0.38-1
mysql-devel - update to 8.0.38-1
mysql-errmsg - update to 8.0.38-1
mysql-test - update to 8.0.38-1
mysql-help - update to 8.0.38-1
Dell EMC VxRail Appliance - update to 8.0.311
Storage Protect for Virtual Environments: Data Protection for Hyper-V - update to 8.1.23.0
Storage Protect Client - update to 8.1.23.0
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.23.0
net-misc/curl - update to 8.3.0-r2
curl - update to 8.3.0-1
curl - update to 8.4.0
curl-doc - update to 8.4.0-1
libcurl-minimal - update to 8.4.0-1
libcurl-devel - update to 8.4.0-1
libcurl - update to 8.4.0-1
curl-minimal - update to 8.4.0-1
curl - update to 8.4.0-1
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.4.0-2.el7jbcs, 8.4.0-2.el8jbcs
IBM Rational ClearCase - addressed in versions 9.1.0.6, 10.0.1.1
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.11-r1, 9.3.3.2-r1
IBM QRadar WinCollect Agent - update to 10.1.9
Storage Protect Plus Server - update to 10.1.16.3
EMC NetWorker Server - update to 19.10.0.2
rubygem-foreman_bootdisk (Red Hat package) - update to 21.2.1-1.el8sat
IBM Automation Decision Services - update to 23.0.1 IF003
Junos OS - addressed in versions 23.4R1-S1, 23.4R2, 24.1R1
Chrome OS - update to 114.0.5735.339
IBM Observability with Instana - update to 281

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins