CVE-2015-3144
published 2015-04-24CVE-2015-3144: The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of…
PriorityP341critical9CVSS 2.0
AVNACLAuSCCICAC
EPSS
11.03%
95.4th percentile
The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | curl | < curl 7.42.0-1 (bookworm) | curl 7.42.0-1 (bookworm) |
| debian | debian_linux | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | — | — |
| haxx | curl | >= 0 < 7.42.0-1 | 7.42.0-1 |
| haxx | curl | >= 0 < 7.42.0-1 | 7.42.0-1 |
| haxx | curl | >= 0 < 7.42.0-1 | 7.42.0-1 |
| haxx | curl | >= 0 < 7.42.0-1 | 7.42.0-1 |
| haxx | curl | >= 0 < 7.35.0-1ubuntu2.5 | 7.35.0-1ubuntu2.5 |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| haxx | libcurl | — | — |
| oracle | mysql_enterprise_monitor | <= 2.3.20 | — |
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv9.0CRITICAL
vendor_debian9.0CRITICAL
vendor_redhat9.0CRITICAL
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w3rm-phr3-x8q8: The fix_hostname function in cURL and libcurl 7
ghsa_unreviewed·2022-05-14
CVE-2015-3144 [HIGH] CWE-119 GHSA-w3rm-phr3-x8q8: The fix_hostname function in cURL and libcurl 7
The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."
OSV
curl vulnerabilities
osv·2015-04-30·CVSS 5.0
CVE-2015-3143 [MEDIUM] curl vulnerabilities
curl vulnerabilities
Paras Sethia discovered that curl could incorrectly re-use NTLM HTTP
credentials when subsequently connecting to the same host over HTTP.
(CVE-2015-3143)
Hanno Böck discovered that curl incorrectly handled zero-length host names.
If a user or automated system were tricked into using a specially crafted
host name, an attacker could possibly use this issue to cause curl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 14.10 and Ubuntu 15.04.
(CVE-2015-3144)
Hanno Böck discovered that curl incorrectly handled cookie path elements.
If a user or automated system were tricked into parsing a specially crafted
cookie, an attacker could possibly use this issue to cause curl to crash,
resulting in a denial of serv
OSV
CVE-2015-3144: The fix_hostname function in cURL and libcurl 7
osv·2015-04-24·CVSS 9.0
CVE-2015-3144 [CRITICAL] CVE-2015-3144: The fix_hostname function in cURL and libcurl 7
The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."
Ubuntu
curl vulnerabilities
vendor_ubuntu·2015-04-30·CVSS 5.0
CVE-2015-3143 [MEDIUM] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Paras Sethia discovered that curl could incorrectly re-use NTLM HTTP
credentials when subsequently connecting to the same host over HTTP.
(CVE-2015-3143)
Hanno Böck discovered that curl incorrectly handled zero-length host names.
If a user or automated system were tricked into using a specially crafted
host name, an attacker could possibly use this issue to cause curl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 14.10 and Ubuntu 15.04.
(CVE-2015-3144)
Hanno Böck discovered that curl incorrectly handled cookie path elements.
If a user or automated system were tricked into parsing a specially crafted
cookie, an attacker could possibly use thi
Red Hat
curl: host name out of boundary memory access
vendor_redhat·2015-04-22·CVSS 9.0
CVE-2015-3144 [CRITICAL] CWE-125 curl: host name out of boundary memory access
curl: host name out of boundary memory access
The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."
It was discovered that libcurl did not properly process zero-length host names. If an attacker could trick an application using libcurl into processing zero-length host names, this could lead to an out-of-bounds read, and possibly cause that application to crash.
Statement: Not vulnerable. This issue does not affect the version of curl as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: curl (Red Hat Ceph Storage 1.2)
Debian
CVE-2015-3144: curl - The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not pro...
vendor_debian·2015·CVSS 9.0
CVE-2015-3144 [CRITICAL] CVE-2015-3144: curl - The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not pro...
The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."
Scope: local
bookworm: resolved (fixed in 7.42.0-1)
bullseye: resolved (fixed in 7.42.0-1)
forky: resolved (fixed in 7.42.0-1)
sid: resolved (fixed in 7.42.0-1)
trixie: resolved (fixed in 7.42.0-1)
Apple
CVE-2015-3144: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 9.0
CVE-2015-3144 [CRITICAL] CVE-2015-3144: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2015-3144
Component: CVE-2015-3144
No detection rules found.
No public exploits indexed.
HackerOne
SSRF in https://imgur.com/vidgif/url
hackerone·2016-03-12
SSRF in https://imgur.com/vidgif/url
SSRF in https://imgur.com/vidgif/url
Hello,
Short description
https://imgur.com/vidgif/url endpoint is vulnerable to a SSRF vulnerability which allows an attacker to craft connections originating from imgur servers to any destination on the internet and imgur internal network and craft outgoing UDP-packets / telnet-based protocol sessions (for example, to connect to SMTP servers from imgur and send spam).
Why does the vulnerability exist?
imgur allows users to use 'video-to-gif' service. When a user requests conversion of such a video, imgur's servers perform an HTTP request to a user-supplied URL in order to discover the URL-s content-type and length. It is evident that in order to do so imgur utilizes libcurl. However, imgur does not properly validate user input and does not configu
Bugzilla
CVE-2015-3143 CVE-2015-3148 CVE-2015-3145 CVE-2015-3144 mingw-curl: various flaws [epel-7]
bugzilla·2015-04-23·CVSS 5.0
CVE-2015-3143 [MEDIUM] CVE-2015-3143 CVE-2015-3148 CVE-2015-3145 CVE-2015-3144 mingw-curl: various flaws [epel-7]
CVE-2015-3143 CVE-2015-3148 CVE-2015-3145 CVE-2015-3144 mingw-curl: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug for mingw-curl: se
Bugzilla
CVE-2015-3143 CVE-2015-3148 CVE-2015-3145 CVE-2015-3144 mingw-curl: various flaws [fedora-all]
bugzilla·2015-04-23·CVSS 5.0
CVE-2015-3143 [MEDIUM] CVE-2015-3143 CVE-2015-3148 CVE-2015-3145 CVE-2015-3144 mingw-curl: various flaws [fedora-all]
CVE-2015-3143 CVE-2015-3148 CVE-2015-3145 CVE-2015-3144 mingw-curl: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
Bugzilla
CVE-2015-3144 curl: host name out of boundary memory access [fedora-all]
bugzilla·2015-04-22·CVSS 9.0
CVE-2015-3144 [CRITICAL] CVE-2015-3144 curl: host name out of boundary memory access [fedora-all]
CVE-2015-3144 curl: host name out of boundary memory access [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedor
Bugzilla
CVE-2015-3144 curl: host name out of boundary memory access
bugzilla·2015-04-20·CVSS 9.0
CVE-2015-3144 [CRITICAL] CVE-2015-3144 curl: host name out of boundary memory access
CVE-2015-3144 curl: host name out of boundary memory access
There is a private function in libcurl called `fix_hostname()` that removes a
trailing dot from the host name if there is one. The function is called after
the host name has been extracted from the URL libcurl has been told to act on.
If a URL is given with a zero-length host name, like in "http://:80" or just
":80", `fix_hostname()` will index the host name pointer with a -1 offset (as
it blindly assumes a non-zero length) and both read and assign that address.
At best, this gets unnoticed but can also lead to a crash or worse. We have
not researched further what kind of malicious actions that potentially this
could be used for.
We are not aware of any exploits of this flaw.
Affected versions: from libcurl 7.37.0 to and incl
http://curl.haxx.se/docs/adv_20150422D.htmlhttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155957.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/156945.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157017.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157188.htmlhttp://lists.opensuse.org/opensuse-updates/2015-04/msg00057.htmlhttp://www.debian.org/security/2015/dsa-3232http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlhttp://www.securityfocus.com/bid/74300http://www.securitytracker.com/id/1032232http://www.ubuntu.com/usn/USN-2591-1https://security.gentoo.org/glsa/201509-02https://support.apple.com/kb/HT205031http://curl.haxx.se/docs/adv_20150422D.htmlhttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10743http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155957.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/156945.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157017.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/157188.htmlhttp://lists.opensuse.org/opensuse-updates/2015-04/msg00057.htmlhttp://www.debian.org/security/2015/dsa-3232http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.htmlhttp://www.securityfocus.com/bid/74300http://www.securitytracker.com/id/1032232http://www.ubuntu.com/usn/USN-2591-1https://security.gentoo.org/glsa/201509-02https://support.apple.com/kb/HT205031
2015-04-24
Published