cURL CVE-2018-16842 Heap Buffer Overflow Vulnerability
BID:106379
Info
cURL CVE-2018-16842 Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 106379 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2018-16842 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2018 12:00AM |
| Updated: | Oct 31 2018 12:00AM |
| Credit: | Brian Carpenter from Geeknik Labs. |
| Vulnerable: |
Haxx Curl 7.61.1 Haxx Curl 7.61 Haxx Curl 7.60 Haxx Curl 7.59 Haxx Curl 7.58 Haxx Curl 7.56.1 Haxx Curl 7.56 Haxx Curl 7.55.1 Haxx Curl 7.55 Haxx Curl 7.54.1 Haxx Curl 7.54 Haxx Curl 7.53.1 Haxx Curl 7.53 Haxx Curl 7.52 Haxx Curl 7.51 Haxx Curl 7.50.3 Haxx Curl 7.50 Haxx Curl 7.47 Haxx Curl 7.46 Haxx Curl 7.45 Haxx Curl 7.43 Haxx Curl 7.42.1 Haxx Curl 7.36 Haxx Curl 7.34 Haxx Curl 7.33 Haxx Curl 7.32 Haxx Curl 7.31 Haxx Curl 7.30 Haxx Curl 7.25 Haxx Curl 7.23 Haxx Curl 7.22 Haxx Curl 7.21 Haxx Curl 7.20 Haxx Curl 7.19.6 Haxx Curl 7.19.5 Haxx Curl 7.19.4 Haxx Curl 7.19.3 Haxx Curl 7.18.1 Haxx Curl 7.18 Haxx Curl 7.17 Haxx Curl 7.16.4 Haxx Curl 7.15.5 Haxx Curl 7.15.3 Haxx Curl 7.15.2 Haxx Curl 7.15.1 Haxx Curl 7.15 Haxx Curl 7.14.1 Haxx Curl 7.57.0 Haxx Curl 7.52.1 Haxx Curl 7.50.1 Haxx Curl 7.49.0 Haxx Curl 7.48.0 Haxx Curl 7.42.0 Haxx Curl 7.41.0 Haxx Curl 7.40.0 Haxx Curl 7.39.0 Haxx Curl 7.38.0 Haxx Curl 7.37.1 Haxx Curl 7.35.0 Haxx Curl 7.29.0 Haxx Curl 7.28.1 Haxx Curl 7.28.0 Haxx Curl 7.27.0 Haxx Curl 7.26.0 Haxx Curl 7.24.0 Haxx Curl 7.23.1 Haxx Curl 7.21.7 Haxx Curl 7.21.6 Haxx Curl 7.21.5 Haxx Curl 7.21.4 Haxx Curl 7.21.3 Haxx Curl 7.21.2 Haxx Curl 7.21.1 Haxx Curl 7.20.1 Haxx Curl 7.19.7 Haxx Curl 7.19.2 Haxx Curl 7.19.1 Haxx Curl 7.19.0 Haxx Curl 7.18.2 Haxx Curl 7.17.1 Haxx Curl 7.16.3 Haxx Curl 7.16.2 Haxx Curl 7.16.1 Haxx Curl 7.16.0 Haxx Curl 7.15.4 |
| Not Vulnerable: |
Haxx Curl 7.62 |
Solution / Fix
cURL CVE-2018-16842 Heap Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
cURL CVE-2018-16842 Heap Buffer Overflow Vulnerability
References:
References:
- Curl Github Repository (Github)
- Curl Home Page (Daniel Stenberg)
- Curl Product Page (Haxx)
- voutf: fix bad arethmetic when outputting warnings to stderr (Github)
- [SECURITY] [DLA 1568-1] curl security update (Debian)
- CVE-2018-16842 curl: Heap-based buffer over-read in the curl tool warning format (Redhat)
- Debian Security Advisory (Debian)
- Red Hat Bugzilla �?? Bug 1644124 (Red Hat Bugzilla)
- USN-3805-2: curl vulnerability (Ubuntu)
- warning message out-of-buffer read (Haxx)