CVE-2016-8622
Summary
| CVE | CVE-2016-8622 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-31 21:29:00 UTC |
| Updated | 2023-11-07 02:36:00 UTC |
| Description | The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if this function would be made to allocate a unscape destination buffer larger than 2GB, it would return that new length in a signed 32 bit integer variable, thus the length would get either just truncated or both truncated and turned negative. That could then lead to libcurl writing outside of its heap based buffer. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| cURL/libcURL CVE-2016-8622 Remote Security Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| 1388386 – (CVE-2016-8622) CVE-2016-8622 curl: URL unescape heap overflow via integer truncation | CONFIRM | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Third Party Advisory |
| curl - URL unescape heap overflow via integer truncation | CONFIRM | curl.haxx.se | Patch, Vendor Advisory |
| CPU Oct 2018 | CONFIRM | www.oracle.com | |
| cURL/libcurl Multiple Bugs Let Remote Users Inject Cookies, Reuse Connections, and Execute Arbitrary Code and Let Local Users Obtain Potentially Sensitive Information and Execute Arbitrary Code - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| cURL: Multiple vulnerabilities (GLSA 201701-47) — Gentoo security | GENTOO | security.gentoo.org | Third Party Advisory |
| [R1] LCE 4.8.2 Fixes Multiple Third-party Library Vulnerabilities - Security Advisory | Tenable Network Security | CONFIRM | www.tenable.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.