cURL / libcURL URL Parser Buffer Overflow Vulnerability
BID:15756
Info
cURL / libcURL URL Parser Buffer Overflow Vulnerability
| Bugtraq ID: | 15756 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-4077 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Dec 07 2005 12:00AM |
| Updated: | Mar 19 2008 02:40PM |
| Credit: | Stefan Esser of the Hardened-PHP Project is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Ubuntu Ubuntu Linux 4.1 ppc Ubuntu Ubuntu Linux 4.1 ia64 Ubuntu Ubuntu Linux 4.1 ia32 Trustix Secure Linux 3.0 Trustix Secure Linux 2.2 Trustix Secure Enterprise Linux 2.0 SCO Unixware 7.1.4 Redhat Fedora Core4 Redhat Fedora Core3 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux AS 4 Redhat Desktop 4.0 OpenPKG OpenPKG 2.5 OpenPKG OpenPKG 2.4 OpenPKG OpenPKG 2.3 OpenPKG OpenPKG Current OpenOffice OpenOffice 2.0.1 OpenOffice OpenOffice 2.0 Beta OpenOffice OpenOffice 1.9.79 OpenOffice OpenOffice 1.1.52 OpenOffice OpenOffice 1.1.51 OpenOffice OpenOffice 1.1.4 OpenOffice OpenOffice 1.1.3 OpenOffice OpenOffice 1.1.2 OpenOffice OpenOffice 1.1.1 OpenOffice OpenOffice 1.1 .0 OpenOffice OpenOffice 1.0.3 OpenOffice OpenOffice 1.0.2 OpenOffice OpenOffice 1.0.1 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 Mandriva Linux Mandrake 10.2 x86_64 Mandriva Linux Mandrake 10.2 Mandriva Linux Mandrake 10.1 x86_64 Mandriva Linux Mandrake 10.1 Gentoo Linux Electric Sheep Electric Sheep 2.6.3 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 Daniel Stenberg curl 7.15 Daniel Stenberg curl 7.14.1 Daniel Stenberg curl 7.14 Daniel Stenberg curl 7.13.2 Daniel Stenberg curl 7.13.1 Daniel Stenberg curl 7.13 Daniel Stenberg curl 7.13 Daniel Stenberg curl 7.12.3 Daniel Stenberg curl 7.12.2 Daniel Stenberg curl 7.12.1 Daniel Stenberg curl 7.12 Daniel Stenberg curl 7.11.2 Cosmicperl Directory Pro 10.0.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.4.9 Apple Mac OS X Server 10.4.8 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X Server 10.3.9 Apple Mac OS X Server 10.3.8 Apple Mac OS X Server 10.3.7 Apple Mac OS X Server 10.3.6 Apple Mac OS X Server 10.3.5 Apple Mac OS X Server 10.3.4 Apple Mac OS X Server 10.3.3 Apple Mac OS X Server 10.3.2 Apple Mac OS X Server 10.3.1 Apple Mac OS X Server 10.3 Apple Mac OS X Server 10.2.8 Apple Mac OS X Server 10.2.7 Apple Mac OS X Server 10.2.6 Apple Mac OS X Server 10.2.5 Apple Mac OS X Server 10.2.4 Apple Mac OS X Server 10.2.3 Apple Mac OS X Server 10.2.2 Apple Mac OS X Server 10.2.1 Apple Mac OS X Server 10.2 Apple Mac OS X Server 10.1.5 Apple Mac OS X Server 10.1.4 Apple Mac OS X Server 10.1.3 Apple Mac OS X Server 10.1.2 Apple Mac OS X Server 10.1.1 Apple Mac OS X Server 10.1 Apple Mac OS X Server 10.0 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.4.11 Apple Mac OS X 10.4.10 Apple Mac OS X 10.4.9 Apple Mac OS X 10.4.8 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.3.9 Apple Mac OS X 10.3.8 Apple Mac OS X 10.3.7 Apple Mac OS X 10.3.6 Apple Mac OS X 10.3.5 Apple Mac OS X 10.3.4 Apple Mac OS X 10.3.3 Apple Mac OS X 10.3.2 Apple Mac OS X 10.3.1 Apple Mac OS X 10.3 Apple Mac OS X 10.2.8 Apple Mac OS X 10.2.7 Apple Mac OS X 10.2.6 Apple Mac OS X 10.2.5 Apple Mac OS X 10.2.4 Apple Mac OS X 10.2.3 Apple Mac OS X 10.2.2 Apple Mac OS X 10.2.1 Apple Mac OS X 10.2 Apple Mac OS X 10.1.5 Apple Mac OS X 10.1.4 Apple Mac OS X 10.1.3 Apple Mac OS X 10.1.2 Apple Mac OS X 10.1.1 Apple Mac OS X 10.1 Apple Mac OS X 10.1 Apple Mac OS X 10.0.4 Apple Mac OS X 10.0.3 Apple Mac OS X 10.0.2 Apple Mac OS X 10.0.1 Apple Mac OS X 10.0 3 Apple Mac OS X 10.0 Apple Mac OS X 10.5 |
| Not Vulnerable: |
OpenOffice OpenOffice 2.0.2 Daniel Stenberg curl 7.15.1 |
Discussion
cURL / libcURL URL Parser Buffer Overflow Vulnerability
cURL and libcURL are prone to a buffer-overflow vulnerability. This issue is due to a failure in the library to perform proper bounds checks on user-supplied data before using it in a finite-sized buffer.
The issues occur when the URL parser function handles an excessively long URL string.
An attacker can exploit this issue to crash the affected library, effectively denying service. Arbitrary code execution may also be possible, which may facilitate a compromise of the underlying system.
cURL and libcURL are prone to a buffer-overflow vulnerability. This issue is due to a failure in the library to perform proper bounds checks on user-supplied data before using it in a finite-sized buffer.
The issues occur when the URL parser function handles an excessively long URL string.
An attacker can exploit this issue to crash the affected library, effectively denying service. Arbitrary code execution may also be possible, which may facilitate a compromise of the underlying system.
Exploit / POC
cURL / libcURL URL Parser Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
cURL / libcURL URL Parser Buffer Overflow Vulnerability
Solution:
Please see the referenced advisories for more information.
OpenOffice OpenOffice 1.0.1
OpenOffice OpenOffice 1.1.51
Apple Mac OS X 10.4.11
Apple Mac OS X Server 10.4.11
Apple Mac OS X 10.5.2
Apple Mac OS X Server 10.5.2
Daniel Stenberg curl 7.11.2
Daniel Stenberg curl 7.13.1
Daniel Stenberg curl 7.14
Daniel Stenberg curl 7.15
Solution:
Please see the referenced advisories for more information.
OpenOffice OpenOffice 1.0.1
-
OpenOffice OpenOffice 2.0.2
http://download.openoffice.org/2.0.2/index.html
OpenOffice OpenOffice 1.1.51
-
OpenOffice OpenOffice 2.0.2
http://download.openoffice.org/2.0.2/index.html
Apple Mac OS X 10.4.11
-
Apple SecUpd2008-002PPC.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpd2008-002PPC.dmg -
Apple SecUpd2008-002Univ.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpd2008-002Univ.dmg
Apple Mac OS X Server 10.4.11
-
Apple SecUpdSrvr2008-002PPC.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpdSrvr2008-002PPC.dmg -
Apple SecUpdSrvr2008-002Univ.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpdSrvr2008-002Univ.dmg
Apple Mac OS X 10.5.2
-
Apple SecUpd2008-002.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpd2008-002.dmg
Apple Mac OS X Server 10.5.2
-
Apple SecUpdSrvr2008-002.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpdSrvr2008-002.dmg
Daniel Stenberg curl 7.11.2
-
Daniel Stenberg curl-7.15.1.tar.gz
http://curl.haxx.se/download/curl-7.15.1.tar.gz -
Mandriva curl-7.13.1-2.2.102mdk.i586.rpm
Mandriva Linux 10.2:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva curl-7.13.1-2.2.102mdk.x86_64.rpm
Mandriva Linux 10.2/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva lib64curl3-7.13.1-2.2.102mdk.x86_64.rpm
Mandriva Linux 10.2/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva lib64curl3-devel-7.13.1-2.2.102mdk.x86_64.rpm
Mandriva Linux 10.2/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva libcurl3-7.13.1-2.2.102mdk.i586.rpm
Mandriva Linux 10.2:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva libcurl3-devel-7.13.1-2.2.102mdk.i586.rpm
Mandriva Linux 10.2:
http://www1.mandrivalinux.com/en/ftp.php3 -
Ubuntu libcurl2-dev_7.11.2-12ubuntu3.3_amd64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/universe/c/curl/libcurl2-dev_7. 11.2-12ubuntu3.3_amd64.deb -
Ubuntu libcurl2-dev_7.11.2-12ubuntu3.3_i386.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/universe/c/curl/libcurl2-dev_7. 11.2-12ubuntu3.3_i386.deb -
Ubuntu libcurl2-dev_7.11.2-12ubuntu3.3_powerpc.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/universe/c/curl/libcurl2-dev_7. 11.2-12ubuntu3.3_powerpc.deb -
Ubuntu libcurl2_7.11.2-12ubuntu3.3_amd64.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/universe/c/curl/libcurl2_7.11.2 -12ubuntu3.3_amd64.deb -
Ubuntu libcurl2_7.11.2-12ubuntu3.3_i386.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/universe/c/curl/libcurl2_7.11.2 -12ubuntu3.3_i386.deb -
Ubuntu libcurl2_7.11.2-12ubuntu3.3_powerpc.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/universe/c/curl/libcurl2_7.11.2 -12ubuntu3.3_powerpc.deb -
Ubuntu libcurl3-dbg_7.12.3-2ubuntu3.5_i386.deb
Ubuntu 5.04 (Hoary Hedgehog)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/libcurl3-dbg_7.12.3 -2ubuntu3.5_i386.deb
Daniel Stenberg curl 7.13.1
-
Daniel Stenberg curl-7.15.1.tar.gz
http://curl.haxx.se/download/curl-7.15.1.tar.gz -
Mandriva libcurl3-devel-7.13.1-2.2.102mdk.i586.rpm
Mandriva Linux 10.2:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva curl-7.13.1-2.1.102mdk.i586.rpm
Mandrivalinux 10.2:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva curl-7.13.1-2.1.102mdk.x86_64.rpm
Mandrivalinux 10.2/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3
Daniel Stenberg curl 7.14
-
Daniel Stenberg curl-7.15.1.tar.gz
http://curl.haxx.se/download/curl-7.15.1.tar.gz -
Mandriva lib64curl3-devel-7.14.0-2.2.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva curl-7.14.0-2.2.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva curl-7.14.0-2.2.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva lib64curl3-7.14.0-2.2.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva lib64curl3-devel-7.14.0-2.2.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva libcurl3-7.14.0-2.2.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva libcurl3-devel-7.14.0-2.2.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva php-curl-5.0.4-1.1.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://www1.mandrivalinux.com/en/ftp.php3 -
Mandriva php-curl-5.0.4-1.1.20060mdk.x86_64.rpm
Mandriva Linux 2006.0/X86_64:
http://www1.mandrivalinux.com/en/ftp.php3 -
Trustix curl-7.15.1-1tr.i586.rpm
Trustix Secure Linux 2.2
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix curl-7.15.1-1tr.i586.rpm
Trustix Secure Linux 3.0
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix curl-devel-7.15.1-1tr.i586.rpm
Trustix Secure Linux 2.2
ftp://ftp.trustix.org/pub/trustix/updates/ -
Trustix curl-devel-7.15.1-1tr.i586.rpm
Trustix Secure Linux 3.0
ftp://ftp.trustix.org/pub/trustix/updates/ -
Ubuntu curl_7.14.0-2ubuntu1.2_amd64.deb
Ubuntu 5.10 (Breezy Badger)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/curl_7.14.0-2ubuntu 1.2_amd64.deb -
Ubuntu curl_7.14.0-2ubuntu1.2_powerpc.deb
Ubuntu 5.10 (Breezy Badger)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/curl_7.14.0-2ubuntu 1.2_powerpc.deb -
Ubuntu libcurl3-dbg_7.14.0-2ubuntu1.2_amd64.deb
Ubuntu 5.10 (Breezy Badger)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/libcurl3-dbg_7.14.0 -2ubuntu1.2_amd64.deb -
Ubuntu libcurl3-dbg_7.14.0-2ubuntu1.2_i386.deb
Ubuntu 5.10 (Breezy Badger)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/libcurl3-dbg_7.14.0 -2ubuntu1.2_i386.deb -
Ubuntu libcurl3-dbg_7.14.0-2ubuntu1.2_powerpc.deb
Ubuntu 5.10 (Breezy Badger)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/libcurl3-dbg_7.14.0 -2ubuntu1.2_powerpc.deb -
Ubuntu libcurl3-dev_7.14.0-2ubuntu1.2_amd64.deb
Ubuntu 5.10 (Breezy Badger)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/libcurl3-dev_7.14.0 -2ubuntu1.2_amd64.deb -
Ubuntu libcurl3-dev_7.14.0-2ubuntu1.2_i386.deb
Ubuntu 5.10 (Breezy Badger)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/libcurl3-dev_7.14.0 -2ubuntu1.2_i386.deb -
Ubuntu libcurl3-dev_7.14.0-2ubuntu1.2_powerpc.deb
Ubuntu 5.10 (Breezy Badger)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/libcurl3-dev_7.14.0 -2ubuntu1.2_powerpc.deb -
Ubuntu libcurl3-gssapi_7.14.0-2ubuntu1.2_amd64.deb
Ubuntu 5.10 (Breezy Badger)
http://security.ubuntu.com/ubuntu/pool/universe/c/curl/libcurl3-gssapi _7.14.0-2ubuntu1.2_amd64.deb -
Ubuntu libcurl3-gssapi_7.14.0-2ubuntu1.2_i386.deb
Ubuntu 5.10 (Breezy Badger)
http://security.ubuntu.com/ubuntu/pool/universe/c/curl/libcurl3-gssapi _7.14.0-2ubuntu1.2_i386.deb -
Ubuntu libcurl3-gssapi_7.14.0-2ubuntu1.2_powerpc.deb
Ubuntu 5.10 (Breezy Badger)
http://security.ubuntu.com/ubuntu/pool/universe/c/curl/libcurl3-gssapi _7.14.0-2ubuntu1.2_powerpc.deb -
Ubuntu libcurl3_7.14.0-2ubuntu1.2_amd64.deb
Ubuntu 5.10 (Breezy Badger)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/libcurl3_7.14.0-2ub untu1.2_amd64.deb -
Ubuntu libcurl3_7.14.0-2ubuntu1.2_i386.deb
Ubuntu 5.10 (Breezy Badger)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/libcurl3_7.14.0-2ub untu1.2_i386.deb -
Ubuntu libcurl3_7.14.0-2ubuntu1.2_powerpc.deb
Ubuntu 5.10 (Breezy Badger)
http://security.ubuntu.com/ubuntu/pool/main/c/curl/libcurl3_7.14.0-2ub untu1.2_powerpc.deb
Daniel Stenberg curl 7.15
-
Daniel Stenberg curl-7.15.1.tar.gz
http://curl.haxx.se/download/curl-7.15.1.tar.gz
References
cURL / libcURL URL Parser Buffer Overflow Vulnerability
References:
References:
- cURL changelog (Daniel Stenberg
) - Curl Home Page (Daniel Stenberg)
- Issue 59032 (OpenOffice)
- libcurl URL Buffer Overflow Vulnerability (Daniel Stenberg)
- libcurl URL Parsing Vulnerability (Hardened-PHP Project)
- OpenOffice Homepage (OpenOffice)
- RHSA-2005:875-4 - curl security update (RedHat)
- Multiple Network-related Vulnerabilities in Electric Sheep ([email protected])