Out-of-bounds read in cURL - CVE-2024-7264
Published: August 1, 2024 / Updated: October 15, 2024
Vulnerability identifier: #VU95131
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-7264
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the ASN1 parser code in the GTime2str() function. A remote attacker can trigger an out-of-bounds read error and cause a denial of service condition on the system.
Affected software
cURL
RecoverPoint for Virtual Machines
IBM MaaS360 Cloud Extender Agent
EasyApache
IBM Rational ClearCase
IBM QRadar WinCollect Agent
IBM Workload Scheduler
Autodesk Infraworks
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
visionOS
PowerSC
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
macOS
Ubuntu
Slackware Linux
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
openSUSE Leap
tvOS
Apple iOS
iPadOS
watchOS
Oracle Solaris
envoy
Communications Unified Assurance
Nessus Network Monitor
MySQL Enterprise Backup
SecurityCenter
LANTIME Operating System Firmware (LTOS)
Oracle Business Intelligence Enterprise Edition
Storage Resource Manager
Cognos Dashboards on Cloud Pak for Data
Dell Policy Manager for Secure Connect Gateway (SCG)
MySQL Server
Oracle Database Server
Oracle Essbase
curl (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl4 (Ubuntu package)
libcurl3 (Ubuntu package)
mecab
mecab-ipadic-EUCJP
mecab-ipadic
curl-debuginfo
libcurl4
curl
libcurl4-debuginfo
curl-debugsource
libcurl4-debuginfo-32bit
libcurl-devel
libcurl4-32bit
libcurl4-32bit-debuginfo
libcurl-devel-32bit
libcurl4-64bit-debuginfo
libcurl4-64bit
libcurl-devel-64bit
mysql-test
mysql-server
mysql-libs
mysql-errmsg
mysql-devel
mysql-common
mysql
mysql (Red Hat package)
libcurl3t64-gnutls (Ubuntu package)
libcurl4t64 (Ubuntu package)
OpenShift Service Mesh
Dell EMC Storage Monitoring and Reporting (SMR)
IBM CICS TX Advanced
RecoverPoint for Virtual Machines
IBM MaaS360 Cloud Extender Agent
EasyApache
IBM Rational ClearCase
IBM QRadar WinCollect Agent
IBM Workload Scheduler
Autodesk Infraworks
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
visionOS
PowerSC
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
macOS
Ubuntu
Slackware Linux
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
Basesystem Module
openSUSE Leap
tvOS
Apple iOS
iPadOS
watchOS
Oracle Solaris
envoy
Communications Unified Assurance
Nessus Network Monitor
MySQL Enterprise Backup
SecurityCenter
LANTIME Operating System Firmware (LTOS)
Oracle Business Intelligence Enterprise Edition
Storage Resource Manager
Cognos Dashboards on Cloud Pak for Data
Dell Policy Manager for Secure Connect Gateway (SCG)
MySQL Server
Oracle Database Server
Oracle Essbase
curl (Ubuntu package)
libcurl3-gnutls (Ubuntu package)
libcurl3-nss (Ubuntu package)
libcurl4 (Ubuntu package)
libcurl3 (Ubuntu package)
mecab
mecab-ipadic-EUCJP
mecab-ipadic
curl-debuginfo
libcurl4
curl
libcurl4-debuginfo
curl-debugsource
libcurl4-debuginfo-32bit
libcurl-devel
libcurl4-32bit
libcurl4-32bit-debuginfo
libcurl-devel-32bit
libcurl4-64bit-debuginfo
libcurl4-64bit
libcurl-devel-64bit
mysql-test
mysql-server
mysql-libs
mysql-errmsg
mysql-devel
mysql-common
mysql
mysql (Red Hat package)
libcurl3t64-gnutls (Ubuntu package)
libcurl4t64 (Ubuntu package)
OpenShift Service Mesh
Dell EMC Storage Monitoring and Reporting (SMR)
IBM CICS TX Advanced
How to mitigate CVE-2024-7264
Install updates from vendor's website.
cURL - update to 8.9.1
visionOS - update to 26.2
envoy - addressed in versions 1.28.6, 1.29.8, 1.30.5, 1.31.1
PowerSC - update to 2.2.0.3
EasyApache - update to 4 2024-8-12
Nessus Network Monitor - update to 6.5.0
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
SecurityCenter - update to SC-202504.2
LANTIME Operating System Firmware (LTOS) - update to 7.08.015
MySQL Server - addressed in versions 8.0.40, 8.4.3
macOS - addressed in versions 14.8.3 23J220, 15.7.3 24G419, 26.2 25C56
tvOS - update to 26.2 23K54
Apple iOS - addressed in versions 18.7.3 22H217, 26.2 23C55
iPadOS - addressed in versions 18.7.3 22H217, 26.2 23C55
Oracle Database Server - update to 23.6
watchOS - update to 26.2 23S303
curl (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.68.0-1ubuntu2.23, 7.81.0-1ubuntu1.17, 8.5.0-2ubuntu10.2
libcurl3-gnutls (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.68.0-1ubuntu2.23, 7.81.0-1ubuntu1.17
libcurl3-nss (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.68.0-1ubuntu2.23, 7.81.0-1ubuntu1.17
libcurl4 (Ubuntu package) - addressed in versions Ubuntu Pro, 7.68.0-1ubuntu2.23, 7.81.0-1ubuntu1.17
libcurl3 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
mecab - update to 0.996-2
OpenShift Service Mesh - update to 2.6.2
mecab-ipadic-EUCJP - update to 2.7.0.20070801-17.0.1
mecab-ipadic - update to 2.7.0.20070801-17.0.1
Storage Resource Manager - update to 5.0.2.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.2.0
Cognos Dashboards on Cloud Pak for Data - update to 5.1
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.26.00.16
curl-debuginfo - addressed in versions 7.66.0-150200.4.75.1, 7.66.0-150200.4.78.1, 8.0.1-11.89.1, 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
libcurl4 - addressed in versions 7.66.0-150200.4.75.1, 7.66.0-150200.4.78.1, 8.0.1-11.89.1, 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
curl - addressed in versions 7.66.0-150200.4.75.1, 7.66.0-150200.4.78.1, 8.0.1-11.89.1, 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
libcurl4-debuginfo - addressed in versions 7.66.0-150200.4.75.1, 7.66.0-150200.4.78.1, 8.0.1-11.89.1, 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
curl-debugsource - addressed in versions 7.66.0-150200.4.75.1, 7.66.0-150200.4.78.1, 8.0.1-11.89.1, 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
libcurl4-debuginfo-32bit - update to 8.0.1-11.89.1
libcurl-devel - addressed in versions 8.0.1-11.89.1, 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
libcurl4-32bit - addressed in versions 8.0.1-11.89.1, 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
libcurl4-32bit-debuginfo - addressed in versions 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
libcurl-devel-32bit - addressed in versions 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
libcurl4-64bit-debuginfo - addressed in versions 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
libcurl4-64bit - addressed in versions 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
libcurl-devel-64bit - addressed in versions 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
mysql-test - update to 8.0.41-1.0.1
mysql-server - update to 8.0.41-1.0.1
mysql-libs - update to 8.0.41-1.0.1
mysql-errmsg - update to 8.0.41-1.0.1
mysql-devel - update to 8.0.41-1.0.1
mysql-common - update to 8.0.41-1.0.1
mysql - update to 8.0.41-1.0.1
mysql (Red Hat package) - update to 8.0.41-2.el9_5
libcurl3t64-gnutls (Ubuntu package) - update to 8.5.0-2ubuntu10.2
libcurl4t64 (Ubuntu package) - update to 8.5.0-2ubuntu10.2
curl - update to 8.9.1
IBM Rational ClearCase - addressed in versions 9.1.0.8, 10.0.1.3, 11.0.0.3
IBM CICS TX Advanced - update to 10.1.0.0 ifix32
IBM QRadar WinCollect Agent - update to 10.1.12
IBM Workload Scheduler - update to 10.2.2
Oracle Solaris - update to 11.4 SRU 77
Autodesk Infraworks - addressed in versions 2022.1.10.363, 2023.1.5.251, 2024.1.4.152, 2025.02.86
visionOS - update to 26.2
envoy - addressed in versions 1.28.6, 1.29.8, 1.30.5, 1.31.1
PowerSC - update to 2.2.0.3
EasyApache - update to 4 2024-8-12
Nessus Network Monitor - update to 6.5.0
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
SecurityCenter - update to SC-202504.2
LANTIME Operating System Firmware (LTOS) - update to 7.08.015
MySQL Server - addressed in versions 8.0.40, 8.4.3
macOS - addressed in versions 14.8.3 23J220, 15.7.3 24G419, 26.2 25C56
tvOS - update to 26.2 23K54
Apple iOS - addressed in versions 18.7.3 22H217, 26.2 23C55
iPadOS - addressed in versions 18.7.3 22H217, 26.2 23C55
Oracle Database Server - update to 23.6
watchOS - update to 26.2 23S303
curl (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.68.0-1ubuntu2.23, 7.81.0-1ubuntu1.17, 8.5.0-2ubuntu10.2
libcurl3-gnutls (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.68.0-1ubuntu2.23, 7.81.0-1ubuntu1.17
libcurl3-nss (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 7.68.0-1ubuntu2.23, 7.81.0-1ubuntu1.17
libcurl4 (Ubuntu package) - addressed in versions Ubuntu Pro, 7.68.0-1ubuntu2.23, 7.81.0-1ubuntu1.17
libcurl3 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
mecab - update to 0.996-2
OpenShift Service Mesh - update to 2.6.2
mecab-ipadic-EUCJP - update to 2.7.0.20070801-17.0.1
mecab-ipadic - update to 2.7.0.20070801-17.0.1
Storage Resource Manager - update to 5.0.2.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.2.0
Cognos Dashboards on Cloud Pak for Data - update to 5.1
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.26.00.16
curl-debuginfo - addressed in versions 7.66.0-150200.4.75.1, 7.66.0-150200.4.78.1, 8.0.1-11.89.1, 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
libcurl4 - addressed in versions 7.66.0-150200.4.75.1, 7.66.0-150200.4.78.1, 8.0.1-11.89.1, 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
curl - addressed in versions 7.66.0-150200.4.75.1, 7.66.0-150200.4.78.1, 8.0.1-11.89.1, 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
libcurl4-debuginfo - addressed in versions 7.66.0-150200.4.75.1, 7.66.0-150200.4.78.1, 8.0.1-11.89.1, 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
curl-debugsource - addressed in versions 7.66.0-150200.4.75.1, 7.66.0-150200.4.78.1, 8.0.1-11.89.1, 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
libcurl4-debuginfo-32bit - update to 8.0.1-11.89.1
libcurl-devel - addressed in versions 8.0.1-11.89.1, 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
libcurl4-32bit - addressed in versions 8.0.1-11.89.1, 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
libcurl4-32bit-debuginfo - addressed in versions 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
libcurl-devel-32bit - addressed in versions 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
libcurl4-64bit-debuginfo - addressed in versions 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
libcurl4-64bit - addressed in versions 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
libcurl-devel-64bit - addressed in versions 8.0.1-150400.5.47.1, 8.6.0-150600.4.3.1
mysql-test - update to 8.0.41-1.0.1
mysql-server - update to 8.0.41-1.0.1
mysql-libs - update to 8.0.41-1.0.1
mysql-errmsg - update to 8.0.41-1.0.1
mysql-devel - update to 8.0.41-1.0.1
mysql-common - update to 8.0.41-1.0.1
mysql - update to 8.0.41-1.0.1
mysql (Red Hat package) - update to 8.0.41-2.el9_5
libcurl3t64-gnutls (Ubuntu package) - update to 8.5.0-2ubuntu10.2
libcurl4t64 (Ubuntu package) - update to 8.5.0-2ubuntu10.2
curl - update to 8.9.1
IBM Rational ClearCase - addressed in versions 9.1.0.8, 10.0.1.3, 11.0.0.3
IBM CICS TX Advanced - update to 10.1.0.0 ifix32
IBM QRadar WinCollect Agent - update to 10.1.12
IBM Workload Scheduler - update to 10.2.2
Oracle Solaris - update to 11.4 SRU 77
Autodesk Infraworks - addressed in versions 2022.1.10.363, 2023.1.5.251, 2024.1.4.152, 2025.02.86
External References
Related Security Bulletins
- Denial of service in cURL
- Slackware Linux update for curl
- Ubuntu update for curl
- SUSE update for curl
- SUSE update for curl
- SUSE update for curl
- Ubuntu update for curl
- SUSE update for curl
- SUSE update for curl
- Multiple vulnerabilities in IBM QRadar WinCollect Agent
- SUSE update for curl
- Envoy update for cURL
- Multiple vulnerabilities in Nessus Network Monitor
- Autodesk InfraWorks update for third-party components
- Multiple vulnerabilities in OpenShift Service Mesh 2.6
- Out-of-bounds read in Oracle Essbase
- Multiple vulnerabilities in Oracle Database Server
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in MySQL Server
- Multiple vulnerabilities in MySQL Enterprise Backup
- cPanel EasyApache update for cURL
- Multiple vulnerabilities in Dell Secure Connect Gateway Policy Manager
- Multiple vulnerabilities in IBM CICS TX Advanced
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- IBM MaaS360 Cloud Extender Agent update for cURL
- Multiple vulnerabilities in IBM PowerSC
- IBM Workload Scheduler update for cURL libcurl
- Oracle Solaris update for third-party components
- Red Hat Enterprise Linux 9 update for mysql
- Red Hat Enterprise Linux 8 update for the mysql:8.0 module
- Multiple vulnerabilities in IBM Rational ClearCase
- Multiple vulnerabilities in IBM Cognos Dashboards on Cloud Pak for Data
- Anolis OS update for mysql:8.0 module
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Tenable Security Center update for third-party components
- Meinberg LANTIME firmware update for curl
- Dell RecoverPoint for Virtual Machines update for third-party components
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in Apple macOS Tahoe
- Multiple vulnerabilities in Apple visionOS
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Apple macOS Sonoma
- Multiple vulnerabilities in Apple iOS 26 and iPadOS 26
- Multiple vulnerabilities in Apple iOS 18 and iPadOS 18
- Multiple vulnerabilities in macOS Sequoia