cURL/libcURL CVE-2018-14618 Heap Buffer Overflow Vulnerability
BID:107835
Info
cURL/libcURL CVE-2018-14618 Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 107835 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2018-14618 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 05 2018 12:00AM |
| Updated: | Sep 05 2018 12:00AM |
| Credit: | Zhaoyang Wu. |
| Vulnerable: |
Ubuntu Ubuntu Linux 18.04 LTS Ubuntu Ubuntu Linux 16.04 LTS Ubuntu Ubuntu Linux 14.04 LTS Ubuntu Ubuntu Linux 12.04 ESM Siemens SINEMA Remote Connect Client 1.0 Redhat Software Collections for RHEL Workstation 7 Redhat Software Collections for RHEL Workstation 6 Redhat Software Collections for RHEL 7 Redhat Software Collections for RHEL 6 Redhat Software Collections 1 for RHEL 7 0 Redhat Software Collections 1 for RHEL 7.6 Redhat Software Collections 1 for RHEL 7.5 Redhat Software Collections 1 for RHEL 7.4 Redhat Software Collections 1 for RHEL 6 Redhat Enterprise Linux 7 Redhat Enterprise Linux 6 Redhat Enterprise Linux 5 Haxx Libcurl 7.61 Haxx Libcurl 7.60 Haxx Libcurl 7.59 Haxx Libcurl 7.58 Haxx Libcurl 7.57 Haxx Libcurl 7.56.1 Haxx Libcurl 7.56 Haxx Libcurl 7.55.1 Haxx Libcurl 7.54.1 Haxx Libcurl 7.54 Haxx Libcurl 7.53.1 Haxx Libcurl 7.53 Haxx Libcurl 7.52 Haxx Libcurl 7.51 Haxx Libcurl 7.50.3 Haxx Libcurl 7.50.2 Haxx Libcurl 7.50.1 Haxx Libcurl 7.50 Haxx Libcurl 7.47 Haxx Libcurl 7.46 Haxx Libcurl 7.43 Haxx Libcurl 7.42.1 Haxx Libcurl 7.36 Haxx Libcurl 7.34 Haxx Libcurl 7.33 Haxx Libcurl 7.32 Haxx Libcurl 7.31 Haxx Libcurl 7.30 Haxx Libcurl 7.25 Haxx Libcurl 7.23 Haxx Libcurl 7.22 Haxx Libcurl 7.21 Haxx Libcurl 7.20 Haxx Libcurl 7.19.6 Haxx Libcurl 7.19.5 Haxx Libcurl 7.19.4 Haxx Libcurl 7.19.3 Haxx Libcurl 7.18.1 Haxx Libcurl 7.18 Haxx Libcurl 7.17 Haxx Libcurl 7.16.4 Haxx Libcurl 7.15.5 Haxx Libcurl 7.55.0 Haxx Libcurl 7.52.1 Haxx Libcurl 7.49.0 Haxx Libcurl 7.48.0 Haxx Libcurl 7.42.0 Haxx Libcurl 7.41.0 Haxx Libcurl 7.40.0 Haxx Libcurl 7.39 Haxx Libcurl 7.38.0 Haxx Libcurl 7.37.1 Haxx Libcurl 7.37.0 Haxx Libcurl 7.35.0 Haxx Libcurl 7.29.0 Haxx Libcurl 7.28.1 Haxx Libcurl 7.28.0 Haxx Libcurl 7.27.0 Haxx Libcurl 7.26.0 Haxx Libcurl 7.24.0 Haxx Libcurl 7.23.1 Haxx Libcurl 7.21.7 Haxx Libcurl 7.21.6 Haxx Libcurl 7.21.5 Haxx Libcurl 7.21.4 Haxx Libcurl 7.21.3 Haxx Libcurl 7.21.2 Haxx Libcurl 7.21.1 Haxx Libcurl 7.20.1 Haxx Libcurl 7.19.7 Haxx Libcurl 7.19.2 Haxx Libcurl 7.19.1 Haxx Libcurl 7.19.0 Haxx Libcurl 7.18.2 Haxx Libcurl 7.17.1 Haxx Libcurl 7.16.3 Haxx Libcurl 7.16.2 Haxx Libcurl 7.16.1 Haxx Libcurl 7.16.0 Haxx Libcurl 7.15.4 |
| Not Vulnerable: |
Siemens SINEMA Remote Connect Client 2.0 HF1 Haxx Libcurl 7.61.1 |
Discussion
cURL/libcURL CVE-2018-14618 Heap Buffer Overflow Vulnerability
cURL/libcURL is prone to a heap-based buffer-overflow vulnerability because it fails to adequately bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Attackers can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will result in denial-of-service conditions.
cURL/libcURL version 7.15.4 through 7.61.0 are vulnerable.
cURL/libcURL is prone to a heap-based buffer-overflow vulnerability because it fails to adequately bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Attackers can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will result in denial-of-service conditions.
cURL/libcURL version 7.15.4 through 7.61.0 are vulnerable.
Exploit / POC
cURL/libcURL CVE-2018-14618 Heap Buffer Overflow Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
cURL/libcURL CVE-2018-14618 Heap Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
cURL/libcURL CVE-2018-14618 Heap Buffer Overflow Vulnerability
References:
References:
- [PATCH] Curl_ntlm_core_mk_nt_hash: return error on too long password (Github)
- cURL Home Page (cURL)
- NTLM password overflow via integer overflow (Haxx)
- Red Hat Bugzilla �?? Bug 1622707 (Red Hat Bugzilla)
- Advisory (ICSA-19-099-04) (ICS CERT)
- Curl_ntlm_core_mk_nt_hash: return error on too long password (Github)
- CVE-2018-14618 curl: NTLM password overflow via integer overflow (Redhat)
- DSA-4286-1 curl -- security update (Debian)
- RHSA-2018:3558 - Security Advisory (Redhat)
- SSA-436177: Multiple Vulnerabilities in SINEMA Remote Connect (Siemens)
- USN-3765-1: curl vulnerability (Ubuntu)
- USN-3765-2: curl vulnerability (Ubuntu)