CVE-2018-1000301
published 2018-05-24CVE-2018-1000301: curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be…
PriorityP345critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
6.00%
92.6th percentile
curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability appears to have been fixed in curl = 7.60.0.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | curl | < curl 7.60.0-1 (bookworm) | curl 7.60.0-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| haxx | curl | >= 0 < 7.60.0-1 | 7.60.0-1 |
| haxx | curl | >= 0 < 7.60.0-1 | 7.60.0-1 |
| haxx | curl | >= 0 < 7.60.0-1 | 7.60.0-1 |
| haxx | curl | >= 0 < 7.60.0-1 | 7.60.0-1 |
| haxx | curl | >= 0 < 7.35.0-1ubuntu2.16 | 7.35.0-1ubuntu2.16 |
| haxx | curl | >= 0 < 7.47.0-1ubuntu2.8 | 7.47.0-1ubuntu2.8 |
| haxx | curl | >= 0 < 7.58.0-2ubuntu3.1 | 7.58.0-2ubuntu3.1 |
| haxx | curl | 7.20.0 – 7.59.0 | — |
| oracle | communications_webrtc_session_controller | < 7.2 | 7.2 |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| oracle | peoplesoft_enterprise_peopletools | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian9.1CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
cURL up to 7.59.0 RTSP memory corruption (RHSA-2018:3157 / Nessus ID 109931)
vuldb·2026-04-16·CVSS 9.1
CVE-2018-1000301 [CRITICAL] cURL up to 7.59.0 RTSP memory corruption (RHSA-2018:3157 / Nessus ID 109931)
A vulnerability labeled as critical has been found in cURL up to 7.59.0. This affects an unknown function of the component RTSP Handler. The manipulation results in memory corruption.
This vulnerability is known as CVE-2018-1000301. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
GHSA
GHSA-32q7-x7q9-wcf9: curl version curl 7
ghsa_unreviewed·2022-05-13
CVE-2018-1000301 [CRITICAL] CWE-125 GHSA-32q7-x7q9-wcf9: curl version curl 7
curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability appears to have been fixed in curl = 7.60.0.
OSV
CVE-2018-1000301: curl version curl 7
osv·2018-05-24·CVSS 9.1
CVE-2018-1000301 [CRITICAL] CVE-2018-1000301: curl version curl 7
curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability appears to have been fixed in curl = 7.60.0.
OSV
curl vulnerabilities
osv·2018-05-16·CVSS 9.8
CVE-2018-1000300 [CRITICAL] curl vulnerabilities
curl vulnerabilities
Dario Weisser discovered that curl incorrectly handled long FTP server
command replies. If a user or automated system were tricked into connecting
to a malicious FTP server, a remote attacker could use this issue to cause
curl to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 17.10 and Ubuntu 18.04 LTS.
(CVE-2018-1000300)
Max Dymond discovered that curl incorrectly handled certain RTSP responses.
If a user or automated system were tricked into connecting to a malicious
server, a remote attacker could use this issue to cause curl to crash,
resulting in a denial of service, or possibly obtain sensitive information.
(CVE-2018-1000301)
Ubuntu
curl vulnerabilities
vendor_ubuntu·2018-05-24·CVSS 9.8
CVE-2018-1000120 [CRITICAL] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
USN-3598-1 fixed a vulnerability in curl. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Phan Thanh discovered that curl incorrectly handled certain FTP paths. An
attacker could use this to cause a denial of service or possibly execute
arbitrary code. (CVE-2018-1000120)
Dario Weisser discovered that curl incorrectly handled certain LDAP URLs.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2018-1000121)
Max Dymond discovered that curl incorrectly handled certain RTSP data. An
attacker could possibly use this to cause a denial of service or even to
get access to sensitive data. (CVE-2018-1000122)
Max Dymond discovered that curl
Ubuntu
curl vulnerabilities
vendor_ubuntu·2018-05-16·CVSS 9.8
CVE-2018-1000300 [CRITICAL] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Dario Weisser discovered that curl incorrectly handled long FTP server
command replies. If a user or automated system were tricked into connecting
to a malicious FTP server, a remote attacker could use this issue to cause
curl to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 17.10 and Ubuntu 18.04 LTS.
(CVE-2018-1000300)
Max Dymond discovered that curl incorrectly handled certain RTSP responses.
If a user or automated system were tricked into connecting to a malicious
server, a remote attacker could use this issue to cause curl to crash,
resulting in a denial of service, or possibly obtain sensitive information.
(CVE-2018-1000301)
Instructions:
Red Hat
curl: Out-of-bounds heap read when missing RTSP headers allows information leak or denial of service
vendor_redhat·2018-05-16·CVSS 9.1
CVE-2018-1000301 [CRITICAL] CWE-125 curl: Out-of-bounds heap read when missing RTSP headers allows information leak or denial of service
curl: Out-of-bounds heap read when missing RTSP headers allows information leak or denial of service
curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability appears to have been fixed in curl = 7.60.0.
Package: rh-dotnetcore10-curl (.NET Core 1.0 on Red Hat Enterprise Linux) - Out of support scope
Package: rh-dotnetcore11-curl (.NET Core 1.1 on Red Hat Enterprise Linux) - Out of support scope
Package: rh-dotnet20-curl (.NET Core 2.0 on Red Hat Enterprise Linux) - Out of support scope
Package: rh-dotnet21-curl (.NET Core 2.1 on Red Hat Enterprise Linux) - Will not f
Debian
CVE-2018-1000301: curl - curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer...
vendor_debian·2018·CVSS 9.1
CVE-2018-1000301 [CRITICAL] CVE-2018-1000301: curl - curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer...
curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability appears to have been fixed in curl = 7.60.0.
Scope: local
bookworm: resolved (fixed in 7.60.0-1)
bullseye: resolved (fixed in 7.60.0-1)
forky: resolved (fixed in 7.60.0-1)
sid: resolved (fixed in 7.60.0-1)
trixie: resolved (fixed in 7.60.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1000300 CVE-2018-1000301 curl: various flaws [fedora-all]
bugzilla·2018-05-16·CVSS 9.8
CVE-2018-1000300 [CRITICAL] CVE-2018-1000300 CVE-2018-1000301 curl: various flaws [fedora-all]
CVE-2018-1000300 CVE-2018-1000301 curl: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
Bugzilla
CVE-2018-1000301 curl: Out-of-bounds heap read when missing RTSP headers allows information leak or denial of service
bugzilla·2018-05-07·CVSS 9.1
CVE-2018-1000301 [CRITICAL] CVE-2018-1000301 curl: Out-of-bounds heap read when missing RTSP headers allows information leak or denial of service
CVE-2018-1000301 curl: Out-of-bounds heap read when missing RTSP headers allows information leak or denial of service
curl can be tricked into reading data beyond the end of a heap based buffer
used to store downloaded content.
When servers send RTSP responses back to curl, the data starts out with a set
of headers. curl parses that data to separate it into a number of headers to
deal with those appropriately and to find the end of the headers that signal
the start of the "body" part.
The function that splits up the response into headers is called
`Curl_http_readwrite_headers()` and in situations where it can't find a single
header in the buffer, it might end up leaving a pointer pointing into the
buffer instead of to the start of the buffer which then later on may lead to
an out of buf
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/104225http://www.securitytracker.com/id/1040931https://access.redhat.com/errata/RHBA-2019:0327https://access.redhat.com/errata/RHSA-2018:3157https://access.redhat.com/errata/RHSA-2018:3558https://access.redhat.com/errata/RHSA-2020:0544https://access.redhat.com/errata/RHSA-2020:0594https://curl.haxx.se/docs/adv_2018-b138.htmlhttps://lists.debian.org/debian-lts-announce/2018/05/msg00010.htmlhttps://security.gentoo.org/glsa/201806-05https://usn.ubuntu.com/3598-2/https://usn.ubuntu.com/3648-1/https://www.debian.org/security/2018/dsa-4202https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.securityfocus.com/bid/104225http://www.securitytracker.com/id/1040931https://access.redhat.com/errata/RHBA-2019:0327https://access.redhat.com/errata/RHSA-2018:3157https://access.redhat.com/errata/RHSA-2018:3558https://access.redhat.com/errata/RHSA-2020:0544https://access.redhat.com/errata/RHSA-2020:0594https://curl.haxx.se/docs/adv_2018-b138.htmlhttps://lists.debian.org/debian-lts-announce/2018/05/msg00010.htmlhttps://security.gentoo.org/glsa/201806-05https://usn.ubuntu.com/3598-2/https://usn.ubuntu.com/3648-1/https://www.debian.org/security/2018/dsa-4202https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
2018-05-24
Published