CVE-2018-1000300
published 2018-05-24CVE-2018-1000300: curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122: Heap-based Buffer Overflow vulnerability in denial of service and more that can…
PriorityP350critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.86%
90.9th percentile
curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122: Heap-based Buffer Overflow vulnerability in denial of service and more that can result in curl might overflow a heap based memory buffer when closing down an FTP connection with very long server command replies.. This vulnerability appears to have been fixed in curl = 7.60.0.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | curl | < curl 7.60.0-1 (bookworm) | curl 7.60.0-1 (bookworm) |
| haxx | curl | >= 0 < 7.60.0-1 | 7.60.0-1 |
| haxx | curl | >= 0 < 7.60.0-1 | 7.60.0-1 |
| haxx | curl | >= 0 < 7.60.0-1 | 7.60.0-1 |
| haxx | curl | >= 0 < 7.60.0-1 | 7.60.0-1 |
| haxx | curl | >= 0 < 7.35.0-1ubuntu2.16 | 7.35.0-1ubuntu2.16 |
| haxx | curl | >= 0 < 7.47.0-1ubuntu2.8 | 7.47.0-1ubuntu2.8 |
| haxx | curl | >= 0 < 7.58.0-2ubuntu3.1 | 7.58.0-2ubuntu3.1 |
| haxx | curl | 7.54.1 – 7.59.0 | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
curl vulnerabilities
vendor_ubuntu·2018-05-16·CVSS 9.8
CVE-2018-1000300 [CRITICAL] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Dario Weisser discovered that curl incorrectly handled long FTP server
command replies. If a user or automated system were tricked into connecting
to a malicious FTP server, a remote attacker could use this issue to cause
curl to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 17.10 and Ubuntu 18.04 LTS.
(CVE-2018-1000300)
Max Dymond discovered that curl incorrectly handled certain RTSP responses.
If a user or automated system were tricked into connecting to a malicious
server, a remote attacker could use this issue to cause curl to crash,
resulting in a denial of service, or possibly obtain sensitive information.
(CVE-2018-1000301)
Instructions:
Red Hat
curl: FTP shutdown response heap-based buffer overflow can potentially lead to RCE
vendor_redhat·2018-05-16·CVSS 9.8
CVE-2018-1000300 [CRITICAL] CWE-122 curl: FTP shutdown response heap-based buffer overflow can potentially lead to RCE
curl: FTP shutdown response heap-based buffer overflow can potentially lead to RCE
curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122: Heap-based Buffer Overflow vulnerability in denial of service and more that can result in curl might overflow a heap based memory buffer when closing down an FTP connection with very long server command replies.. This vulnerability appears to have been fixed in curl = 7.60.0.
Package: rh-dotnetcore10-curl (.NET Core 1.0 on Red Hat Enterprise Linux) - Not affected
Package: rh-dotnetcore11-curl (.NET Core 1.1 on Red Hat Enterprise Linux) - Not affected
Package: rh-dotnet20-curl (.NET Core 2.0 on Red Hat Enterprise Linux) - Not affected
Package: curl (Red Hat Enterprise Linux 5) - Not affected
Package: curl (Red Hat Enterprise Linux
Debian
CVE-2018-1000300: curl - curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122: Heap-b...
vendor_debian·2018·CVSS 9.8
CVE-2018-1000300 [CRITICAL] CVE-2018-1000300: curl - curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122: Heap-b...
curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122: Heap-based Buffer Overflow vulnerability in denial of service and more that can result in curl might overflow a heap based memory buffer when closing down an FTP connection with very long server command replies.. This vulnerability appears to have been fixed in curl = 7.60.0.
Scope: local
bookworm: resolved (fixed in 7.60.0-1)
bullseye: resolved (fixed in 7.60.0-1)
forky: resolved (fixed in 7.60.0-1)
sid: resolved (fixed in 7.60.0-1)
trixie: resolved (fixed in 7.60.0-1)
GHSA
GHSA-5vcr-2m3x-3m96: curl version curl 7
ghsa_unreviewed·2022-05-13
CVE-2018-1000300 [CRITICAL] CWE-787 GHSA-5vcr-2m3x-3m96: curl version curl 7
curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122: Heap-based Buffer Overflow vulnerability in denial of service and more that can result in curl might overflow a heap based memory buffer when closing down an FTP connection with very long server command replies.. This vulnerability appears to have been fixed in curl = 7.60.0.
OSV
CVE-2018-1000300: curl version curl 7
osv·2018-05-24·CVSS 9.8
CVE-2018-1000300 [CRITICAL] CVE-2018-1000300: curl version curl 7
curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122: Heap-based Buffer Overflow vulnerability in denial of service and more that can result in curl might overflow a heap based memory buffer when closing down an FTP connection with very long server command replies.. This vulnerability appears to have been fixed in curl = 7.60.0.
OSV
curl vulnerabilities
osv·2018-05-16·CVSS 9.8
CVE-2018-1000300 [CRITICAL] curl vulnerabilities
curl vulnerabilities
Dario Weisser discovered that curl incorrectly handled long FTP server
command replies. If a user or automated system were tricked into connecting
to a malicious FTP server, a remote attacker could use this issue to cause
curl to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 17.10 and Ubuntu 18.04 LTS.
(CVE-2018-1000300)
Max Dymond discovered that curl incorrectly handled certain RTSP responses.
If a user or automated system were tricked into connecting to a malicious
server, a remote attacker could use this issue to cause curl to crash,
resulting in a denial of service, or possibly obtain sensitive information.
(CVE-2018-1000301)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1000300 mingw-curl: curl: FTP shutdown response heap-based buffer overflow can potentially lead to RCE [fedora-all]
bugzilla·2018-05-16·CVSS 9.8
CVE-2018-1000300 [CRITICAL] CVE-2018-1000300 mingw-curl: curl: FTP shutdown response heap-based buffer overflow can potentially lead to RCE [fedora-all]
CVE-2018-1000300 mingw-curl: curl: FTP shutdown response heap-based buffer overflow can potentially lead to RCE [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE:
Bugzilla
CVE-2018-1000300 CVE-2018-1000301 curl: various flaws [fedora-all]
bugzilla·2018-05-16·CVSS 9.8
CVE-2018-1000300 [CRITICAL] CVE-2018-1000300 CVE-2018-1000301 curl: various flaws [fedora-all]
CVE-2018-1000300 CVE-2018-1000301 curl: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
Bugzilla
CVE-2018-1000300 curl: FTP shutdown response heap-based buffer overflow can potentially lead to RCE
bugzilla·2018-05-07·CVSS 9.8
CVE-2018-1000300 [CRITICAL] CVE-2018-1000300 curl: FTP shutdown response heap-based buffer overflow can potentially lead to RCE
CVE-2018-1000300 curl: FTP shutdown response heap-based buffer overflow can potentially lead to RCE
A heap-based buffer overflow can happen when closing down an FTP connection with very long server command replies.
When doing FTP transfers, curl keeps a spare "closure handle" around internally that will be used when an FTP connection gets shut down since the original curl easy handle is then already removed.
FTP server response data that gets cached from the original transfer might then be larger than the default buffer size (16 KB) allocated in the "closure handle", which can lead to a buffer overwrite. The contents and size of that overwrite is controllable by the server.
This situation was detected by an assert() in the code, but that was of course only preventing bad stuff in debug
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/104207http://www.securitytracker.com/id/1040933https://curl.haxx.se/docs/adv_2018-82c2.htmlhttps://security.gentoo.org/glsa/201806-05https://usn.ubuntu.com/3648-1/https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/104207http://www.securitytracker.com/id/1040933https://curl.haxx.se/docs/adv_2018-82c2.htmlhttps://security.gentoo.org/glsa/201806-05https://usn.ubuntu.com/3648-1/https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
2018-05-24
Published