Multiple Vendor WGet/Curl NTLM Username Buffer Overflow Vulnerability
BID:15102
Info
Multiple Vendor WGet/Curl NTLM Username Buffer Overflow Vulnerability
| Bugtraq ID: | 15102 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-3185 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 13 2005 12:00AM |
| Updated: | May 05 2008 05:56PM |
| Credit: | The discoverer of this vulnerability wishes to remain anonymous; this vulnerability was disclosed in the referenced iDEFENSE advisory. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 4.1 ppc Ubuntu Ubuntu Linux 4.1 ia64 Ubuntu Ubuntu Linux 4.1 ia32 Trustix Secure Linux 3.0 Trustix Secure Linux 2.2 Trustix Secure Enterprise Linux 2.0 SuSE Linux Enterprise Server 9 Slackware Linux 10.2 Slackware Linux 10.1 Slackware Linux 10.0 Slackware Linux 9.1 Slackware Linux 9.0 Slackware Linux 8.1 Slackware Linux -current SGI ProPack 3.0 SP6 SCO Open Server 6.0 SCO Open Server 5.0.7 SCO Open Server 5.0.6 a SCO Open Server 5.0.6 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 Redhat Fedora Core4 Redhat Fedora Core3 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 GNU wget 1.10.1 GNU wget 1.10 Gentoo net-misc/curl 7.14.1 Electric Sheep Electric Sheep 2.6.3 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 Daniel Stenberg curl 7.14.1 Daniel Stenberg curl 7.14 Daniel Stenberg curl 7.13.2 Daniel Stenberg curl 7.13.1 Daniel Stenberg curl 7.13 Daniel Stenberg curl 7.13 Daniel Stenberg curl 7.12.3 Daniel Stenberg curl 7.12.2 Daniel Stenberg curl 7.12.1 Daniel Stenberg curl 7.12 Daniel Stenberg curl 7.11.2 Daniel Stenberg curl 7.11.1 Daniel Stenberg curl 7.11 Daniel Stenberg curl 7.10.8 Daniel Stenberg curl 7.10.7 Daniel Stenberg curl 7.10.6 Daniel Stenberg curl 7.10.5 Daniel Stenberg curl 7.10.4 Daniel Stenberg curl 7.10.3 Daniel Stenberg curl 7.10.2 Daniel Stenberg curl 7.10.1 Daniel Stenberg curl 7.10 Daniel Stenberg curl 7.9.8 Daniel Stenberg curl 7.9.7 Daniel Stenberg curl 7.9.6 Daniel Stenberg curl 7.9.5 Daniel Stenberg curl 7.9.4 Daniel Stenberg curl 7.9.3 Daniel Stenberg curl 7.9.2 Daniel Stenberg curl 7.9.1 Daniel Stenberg curl 7.9 Daniel Stenberg curl 7.8.2 Daniel Stenberg curl 7.8.1 Daniel Stenberg curl 7.8 Daniel Stenberg curl 7.7.3 Daniel Stenberg curl 7.7.2 Daniel Stenberg curl 7.7.1 Daniel Stenberg curl 7.7 Daniel Stenberg curl 7.6.1 Daniel Stenberg curl 7.6 Daniel Stenberg curl 7.5.2 Daniel Stenberg curl 7.5.1 Daniel Stenberg curl 7.5 Daniel Stenberg curl 7.4.2 Daniel Stenberg curl 7.4.1 Daniel Stenberg curl 7.4 Daniel Stenberg curl 7.3 Daniel Stenberg curl 7.2.1 Daniel Stenberg curl 7.2 Daniel Stenberg curl 7.1.1 Daniel Stenberg curl 7.1 Daniel Stenberg curl 6.5.2 Daniel Stenberg curl 6.5.1 Daniel Stenberg curl 6.5 Daniel Stenberg curl 6.4 Daniel Stenberg curl 6.3.1 Daniel Stenberg curl 6.3 Daniel Stenberg curl 6.2 Daniel Stenberg curl 6.1 beta Daniel Stenberg curl 6.1 Daniel Stenberg curl 6.0 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 |
| Not Vulnerable: |
GNU wget 1.10.2 Gentoo net-misc/curl 7.15 .0 Daniel Stenberg curl 7.15 Daniel Stenberg curl 7.13.2 |
Discussion
Multiple Vendor WGet/Curl NTLM Username Buffer Overflow Vulnerability
GNU wget and cURL are prone to a buffer-overflow vulnerability because the applications fail to properly bounds-check user-supplied data before using it in a memory copy operation.
An attacker can exploit this vulnerability to execute arbitrary code in the context of the user running the vulnerable application.
For an exploit to succeed, NTLM authentication must be enabled in the affected clients.
GNU wget and cURL are prone to a buffer-overflow vulnerability because the applications fail to properly bounds-check user-supplied data before using it in a memory copy operation.
An attacker can exploit this vulnerability to execute arbitrary code in the context of the user running the vulnerable application.
For an exploit to succeed, NTLM authentication must be enabled in the affected clients.
Exploit / POC
Multiple Vendor WGet/Curl NTLM Username Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple Vendor WGet/Curl NTLM Username Buffer Overflow Vulnerability
Solution:
An updated version of GNU wget is available.
A security advisory and a patch for cURL have been released.
Please see the referenced vendor advisories for more information.
GNU wget 1.10
GNU wget 1.10.1
Apple Mac OS X Server 10.4
Apple Mac OS X Server 10.4.1
Apple Mac OS X 10.4.2
Apple Mac OS X Server 10.4.3
Apple Mac OS X 10.4.3
SCO Open Server 5.0.6
SCO Open Server 6.0
Daniel Stenberg curl 7.10.7
Daniel Stenberg curl 7.10.8
Daniel Stenberg curl 7.11.2
Daniel Stenberg curl 7.12.2
Daniel Stenberg curl 7.13
Daniel Stenberg curl 7.13.1
Daniel Stenberg curl 7.14
Solution:
An updated version of GNU wget is available.
A security advisory and a patch for cURL have been released.
Please see the referenced vendor advisories for more information.
GNU wget 1.10
-
GNU wget-1.10.2.tar.gz
http://ftp.gnu.org/pub/gnu/wget/wget-1.10.2.tar.gz -
Mandriva wget-1.10-1.1.20060mdk.i586.rpm
Mandrivalinux 2006.0:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva wget-1.10-1.1.20060mdk.x86_64.rpm
Mandrivalinux 2006.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3
GNU wget 1.10.1
-
SUSE wget-1.10.1-2.2.i586.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/wget-1.10.1-2.2. i586.rpm -
SUSE wget-1.10.1-2.2.ppc.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/wget-1.10.1-2.2.p pc.rpm -
SUSE wget-1.10.1-2.2.x86_64.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/wget-1.10.1-2. 2.x86_64.rpm
Apple Mac OS X Server 10.4
-
Apple SecUpdSrvr2005-009Ti.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=08839&cat= 1&platform=osx&method=sa/SecUpdSrvr2005-009Ti.dmg
Apple Mac OS X Server 10.4.1
-
Apple SecUpdSrvr2005-009Ti.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=08839&cat= 1&platform=osx&method=sa/SecUpdSrvr2005-009Ti.dmg
Apple Mac OS X 10.4.2
-
Apple SecUpd2005-009Ti.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=08835&cat= 1&platform=osx&method=sa/SecUpd2005-009Ti.dmg
Apple Mac OS X Server 10.4.3
-
Apple SecUpdSrvr2005-009Ti.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=08839&cat= 1&platform=osx&method=sa/SecUpdSrvr2005-009Ti.dmg
Apple Mac OS X 10.4.3
-
Apple SecUpd2005-009Ti.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=08835&cat= 1&platform=osx&method=sa/SecUpd2005-009Ti.dmg
SCO Open Server 5.0.6
-
SCO gwxlibs210Ba_vol.tar
ftp://ftp.sco.com/pub/openserver5/opensrc/gwxlibs-2.1.0Ba/
SCO Open Server 6.0
-
SCO osr600mp2.iso
ftp://ftp.sco.com/pub/openserver6/600/mp/osr600mp2/osr600mp2.iso
Daniel Stenberg curl 7.10.7
-
Daniel Stenberg libcurl-ntlmbuf.patch
http://curl.haxx.se/libcurl-ntlmbuf.patch -
Slackware curl-7.10.7-i486-2.tgz
Slackware 9.1:
ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/c url-7.10.7-i486-2.tgz
Daniel Stenberg curl 7.10.8
-
Daniel Stenberg libcurl-ntlmbuf.patch
http://curl.haxx.se/libcurl-ntlmbuf.patch
Daniel Stenberg curl 7.11.2
-
Daniel Stenberg libcurl-ntlmbuf.patch
http://curl.haxx.se/libcurl-ntlmbuf.patch
Daniel Stenberg curl 7.12.2
-
Daniel Stenberg libcurl-ntlmbuf.patch
http://curl.haxx.se/libcurl-ntlmbuf.patch -
Slackware curl-7.12.2-i486-2.tgz
Slackware 10.1:
ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/ curl-7.12.2-i486-2.tgz -
Slackware curl-7.12.2-i486-2.tgz
Slackware 10.2:
ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/ curl-7.12.2-i486-2.tgz
Daniel Stenberg curl 7.13
-
Daniel Stenberg libcurl-ntlmbuf.patch
http://curl.haxx.se/libcurl-ntlmbuf.patch -
SUSE curl-7.13.0-5.2.i586.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/curl-7.13.0-5.2.i 586.rpm -
SUSE wget-1.10-1.3.i586.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/i586/wget-1.10-1.3.i58 6.rpm
Daniel Stenberg curl 7.13.1
-
Daniel Stenberg libcurl-ntlmbuf.patch
http://curl.haxx.se/libcurl-ntlmbuf.patch -
Mandriva curl-7.13.1-2.1.102mdk.i586.rpm
Mandrivalinux 10.2:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva curl-7.13.1-2.1.102mdk.x86_64.rpm
Mandrivalinux 10.2/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3
Daniel Stenberg curl 7.14
-
Mandriva curl-7.14.0-2.1.20060mdk.i586.rpm
Mandrivalinux 2006.0:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva curl-7.14.0-2.1.20060mdk.x86_64.rpm
Mandrivalinux 2006.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva lib64curl3-devel-7.14.0-2.1.20060mdk.x86_64.rpm
Mandrivalinux 2006.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva libcurl3-7.14.0-2.1.20060mdk.i586.rpm
Mandrivalinux 2006.0:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva libcurl3-devel-7.14.0-2.1.20060mdk.i586.rpm
Mandrivalinux 2006.0:
http://www1.mandrivalinux.com/en/ftp.php3 -
SUSE curl-32bit-7.14.0-2.2.x86_64.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/curl-32bit-7.1 4.0-2.2.x86_64.rpm -
SUSE curl-32bit-9.3-7.1.x86_64.rpm
SUSE LINUX 9.3:
ftp://ftp.suse.com/pub/suse/i386/update/9.3/rpm/x86_64/curl-32bit-9.3- 7.1.x86_64.rpm -
SUSE curl-7.14.0-2.2.i586.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/i586/curl-7.14.0-2.2. i586.rpm -
SUSE curl-7.14.0-2.2.ppc.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/ppc/curl-7.14.0-2.2.p pc.rpm -
SUSE curl-7.14.0-2.2.x86_64.rpm
SUSE LINUX 10.0:
ftp://ftp.suse.com/pub/suse/i386/update/10.0/rpm/x86_64/curl-7.14.0-2. 2.x86_64.rpm -
Ubuntu curl_7.14.0-2ubuntu1.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/curl_7.14.0-2ubuntu 1.1_amd64.deb -
Ubuntu curl_7.14.0-2ubuntu1.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/curl_7.14.0-2ubuntu 1.1_i386.deb -
Ubuntu curl_7.14.0-2ubuntu1.1_powerpc.deb
Ubuntu 5.10 (Breezy Badger)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/curl_7.14.0-2ubuntu 1.1_powerpc.deb -
Ubuntu libcurl3-dbg_7.14.0-2ubuntu1.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/libcurl3-dbg_7.14.0 -2ubuntu1.1_amd64.deb -
Ubuntu libcurl3-dbg_7.14.0-2ubuntu1.1_i386.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/libcurl3-dbg_7.14.0 -2ubuntu1.1_i386.deb -
Ubuntu libcurl3-dbg_7.14.0-2ubuntu1.1_i386.deb
Ubuntu 5.10 (Breezy Badger)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/libcurl3-dbg_7.14.0 -2ubuntu1.1_i386.deb -
Ubuntu libcurl3-dbg_7.14.0-2ubuntu1.1_powerpc.deb
Ubuntu 5.10 (Breezy Badger)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/libcurl3-dbg_7.14.0 -2ubuntu1.1_powerpc.deb -
Ubuntu libcurl3-dev_7.14.0-2ubuntu1.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/libcurl3-dev_7.14.0 -2ubuntu1.1_amd64.deb -
Ubuntu libcurl3-dev_7.14.0-2ubuntu1.1_i386.deb
Ubuntu 5.10 (Breezy Badger)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/libcurl3-dev_7.14.0 -2ubuntu1.1_i386.deb -
Ubuntu libcurl3-dev_7.14.0-2ubuntu1.1_powerpc.deb
Ubuntu 5.10 (Breezy Badger)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/libcurl3-dev_7.14.0 -2ubuntu1.1_powerpc.deb -
Ubuntu libcurl3-gssapi_7.14.0-2ubuntu1.1_powerpc.deb
Ubuntu 5.10 (Breezy Badger)
http://security.ubuntu.com/ubuntu/pool/universe/c/curl/libcurl3-gssapi _7.14.0-2ubuntu1.1_powerpc.deb -
Ubuntu libcurl3_7.14.0-2ubuntu1.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/libcurl3_7.14.0-2ub untu1.1_amd64.deb -
Ubuntu libcurl3_7.14.0-2ubuntu1.1_i386.deb
Ubuntu 5.10 (Breezy Badger)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/libcurl3_7.14.0-2ub untu1.1_i386.deb -
Ubuntu libcurl3_7.14.0-2ubuntu1.1_powerpc.deb
Ubuntu 5.10 (Breezy Badger)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/libcurl3_7.14.0-2ub untu1.1_powerpc.deb -
Ubuntu wget_1.10-2ubuntu0.1_amd64.deb
Ubuntu 4.10 (Warty Warthog)
http://security.ubuntu.com/ubuntu/pool/main/w/wget/wget_1.10-2ubuntu0. 1_amd64.deb
References
Multiple Vendor WGet/Curl NTLM Username Buffer Overflow Vulnerability
References:
References:
- Curl Home Page (Daniel Stenberg)
- libcurl NTLM Buffer Overflow Vulnerability (Daniel Stenberg)
- Multiple Vendor wget/curl NTLM Username Buffer Overflow Vulnerability (iDEFENSE)
- RHSA-2005:807-6 - curl security update (RedHat)
- RHSA-2005:812-5 - wget security update (RedHat)
- wget Home Page (GNU)
- [gentoo-announce] [ GLSA 200510-19 ] cURL: NTLM username stack overflow (Thierry Carrez
) - Multiple Network-related Vulnerabilities in Electric Sheep ([email protected])