Out-of-bounds read in libcurl - CVE-2017-8817

 

Out-of-bounds read in libcurl - CVE-2017-8817

Published: November 30, 2017


Vulnerability identifier: #VU9459
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-8817
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to redirect the target client to an arbitrary site.

The vulnerability exists due to out-of-bounds read in the FTP wildcard function (CURLOPT_WILDCARDMATCH). A remote unauthenticated attacker can use a string that ends with an '[' character, trigger out-of-bounds read and cause the target connected libcurl client to be redirected.


Affected software

libcurl
Debian Linux
Amazon Linux AMI
Gentoo Linux
Arch Linux
Ubuntu
Slackware Linux
Fedora
curl (Alpine package)
curl
QLogic Virtual Fabric Extension Module for IBM BladeCenter

How to mitigate CVE-2017-8817

Update to version 7.57.0.

curl (Alpine package) - update to 7.57.0-r0
curl - addressed in versions 7.53.1-13.fc26, 7.55.1-8.fc27
QLogic Virtual Fabric Extension Module for IBM BladeCenter - update to 9.0.3.23.00

External References

Related Security Bulletins