Out-of-bounds read in libcurl - CVE-2017-8817
Published: November 30, 2017
Vulnerability details
The vulnerability allows a remote attacker to redirect the target client to an arbitrary site.
The vulnerability exists due to out-of-bounds read in the FTP wildcard function (CURLOPT_WILDCARDMATCH). A remote unauthenticated attacker can use a string that ends with an '[' character, trigger out-of-bounds read and cause the target connected libcurl client to be redirected.
Affected software
Debian Linux
Amazon Linux AMI
Gentoo Linux
Arch Linux
Ubuntu
Slackware Linux
Fedora
curl (Alpine package)
curl
QLogic Virtual Fabric Extension Module for IBM BladeCenter
How to mitigate CVE-2017-8817
curl - addressed in versions 7.53.1-13.fc26, 7.55.1-8.fc27
QLogic Virtual Fabric Extension Module for IBM BladeCenter - update to 9.0.3.23.00
External References
Related Security Bulletins
- Debian update for curl
- Ubuntu update for curl
- Multiple vulnerabilities in libcurl
- Slackware Linux update for curl
- Arch Linux update for curl
- Arch Linux update for libcurl-gnutls
- Arch Linux update for libcurl-compat
- Arch Linux update for lib32-curl
- Arch Linux update for lib32-libcurl-gnutls
- Arch Linux update for lib32-libcurl-compat
- Ubuntu update for curl
- Gentoo update for cURL
- Amazon Linux AMI update for curl
- Out-of-bounds read in curl (Alpine package)
- Multiple vulnerabilities in Qlogic Virtual Fabric Extension Module for IBM BladeCenter Firmware Update
- Fedora 27 update for curl
- Fedora 26 update for curl