CVE-2019-3823
published 2019-02-06CVE-2019-3823: libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer…
PriorityP339high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
4.29%
90.1th percentile
libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read contents will not be returned to the caller.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | curl | < curl 7.64.0-1 (bookworm) | curl 7.64.0-1 (bookworm) |
| debian | debian_linux | — | — |
| haxx | curl | >= 0 < 7.64.0-1 | 7.64.0-1 |
| haxx | curl | >= 0 < 7.64.0-1 | 7.64.0-1 |
| haxx | curl | >= 0 < 7.64.0-1 | 7.64.0-1 |
| haxx | curl | >= 0 < 7.64.0-1 | 7.64.0-1 |
| haxx | curl | >= 0 < 7.35.0-1ubuntu2.20 | 7.35.0-1ubuntu2.20 |
| haxx | curl | >= 0 < 7.47.0-1ubuntu2.12 | 7.47.0-1ubuntu2.12 |
| haxx | curl | >= 0 < 7.58.0-2ubuntu3.6 | 7.58.0-2ubuntu3.6 |
| haxx | libcurl | >= 7.34.0 < 7.64.0 | 7.64.0 |
| oracle | communications_operations_monitor | — | — |
| oracle | communications_operations_monitor | — | — |
| oracle | http_server | — | — |
| oracle | secure_global_desktop | — | — |
| the_curl_project | curl | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SCALANCE and SIMATIC libcurl (Update B)
cisa_ics·2021-03-09·CVSS 4.3
[MEDIUM] Siemens SCALANCE and SIMATIC libcurl (Update B)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE and SIMATIC libcurl (Update B)
Last RevisedSeptember 14, 2021
Alert CodeICSA-21-068-10
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE and SIMATIC
- Vulnerability: Out-of-bounds Read
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the advisory update titled ICSA-21-068-10 Siemens SCALANCE and SIMATIC libcurl (Update A) that was published March 9, 2021, to the ICS webpage on us-cert.cisa.gov.
## 3. RISK EVALUATION
Successful exploitation of this third-pa
CISA ICS
Siemens SINEMA Remote Connect (Update A)
cisa_ics·2019-04-09·CVSS 7.5
[HIGH] Siemens SINEMA Remote Connect (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEMA Remote Connect (Update A)
Last RevisedMarch 09, 2021
Alert CodeICSA-19-099-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.3
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Siemens
- Equipment: SINEMA Remote Connect (Client and Server)
- Vulnerabilities: Incorrect Calculation of Buffer Size, Out-of-bounds Read, Stack-based Buffer Overflow, Improper Handling of Insufficient Permissions
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-19-099-04 Siemens SINEMA Remote Connect that was published Apri
Red Hat
curl: SMTP end-of-response out-of-bounds read
vendor_redhat·2019-02-06·CVSS 4.3
CVE-2019-3823 [MEDIUM] CWE-125 curl: SMTP end-of-response out-of-bounds read
curl: SMTP end-of-response out-of-bounds read
libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read contents will not be returned to the caller.
An out-of-bounds read flaw was found in the way curl handled certain SMTP responses. A remote attacker could use this flaw to crash curl.
Mitigation: Do not use SMTP authentication with curl
Package: rh-dotnetcore10-curl (.NET Core 1.0 on Red Hat Enterprise Linux) - Out of support scope
Package: rh-dotnetcore11-curl (.NET Core 1.1 on Red Hat Enterprise
Ubuntu
curl vulnerabilities
vendor_ubuntu·2019-02-06·CVSS 7.5
CVE-2018-16890 [HIGH] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Wenxiang Qian discovered that curl incorrectly handled certain NTLM
authentication messages. A remote attacker could possibly use this issue to
cause curl to crash, resulting in a denial of service. This issue only
applied to Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 18.10.
(CVE-2018-16890)
Wenxiang Qian discovered that curl incorrectly handled certain NTLMv2
authentication messages. A remote attacker could use this issue to cause
curl to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only applied to Ubuntu 16.04 LTS, Ubuntu 18.04
LTS, and Ubuntu 18.10. (CVE-2019-3822)
Brian Carpenter discovered that curl incorrectly handled certain SMTP
responses. A remote att
Debian
CVE-2019-3823: curl - libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bo...
vendor_debian·2019·CVSS 4.3
CVE-2019-3823 [MEDIUM] CVE-2019-3823: curl - libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bo...
libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read contents will not be returned to the caller.
Scope: local
bookworm: resolved (fixed in 7.64.0-1)
bullseye: resolved (fixed in 7.64.0-1)
forky: resolved (fixed in 7.64.0-1)
sid: resolved (fixed in 7.64.0-1)
trixie: resolved (fixed in 7.64.0-1)
GHSA
GHSA-xmjh-hmw3-hqhr: libcurl versions from 7
ghsa_unreviewed·2022-05-13
CVE-2019-3823 [HIGH] CWE-125 GHSA-xmjh-hmw3-hqhr: libcurl versions from 7
libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read contents will not be returned to the caller.
OSV
curl vulnerabilities
osv·2019-02-06·CVSS 7.5
CVE-2018-16890 [HIGH] curl vulnerabilities
curl vulnerabilities
Wenxiang Qian discovered that curl incorrectly handled certain NTLM
authentication messages. A remote attacker could possibly use this issue to
cause curl to crash, resulting in a denial of service. This issue only
applied to Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 18.10.
(CVE-2018-16890)
Wenxiang Qian discovered that curl incorrectly handled certain NTLMv2
authentication messages. A remote attacker could use this issue to cause
curl to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only applied to Ubuntu 16.04 LTS, Ubuntu 18.04
LTS, and Ubuntu 18.10. (CVE-2019-3822)
Brian Carpenter discovered that curl incorrectly handled certain SMTP
responses. A remote attacker could possibly use this issue to cause curl to
crash, r
OSV
CVE-2019-3823: libcurl versions from 7
osv·2019-02-06·CVSS 7.5
CVE-2019-3823 [HIGH] CVE-2019-3823: libcurl versions from 7
libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read contents will not be returned to the caller.
No detection rules found.
No public exploits indexed.
HackerOne
libcurl: SMTP end-of-response out-of-bounds read - CVE-2019-3823
hackerone·2021-01-08·CVSS 4.3
CVE-2019-3823 [MEDIUM] libcurl: SMTP end-of-response out-of-bounds read - CVE-2019-3823
libcurl: SMTP end-of-response out-of-bounds read - CVE-2019-3823
```
libcurl contains a heap out-of-bounds read in the code handling the
end-of-response for SMTP.
If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains
no character ending the parsed number, and `len` is set to 5, then the
`strtol()` call reads beyond the allocated buffer. The read contents will not
be returned to the caller.
```
The issue was reported to the project on 18 January 2019.
A patch was sent to me on 19 January 2019.
curl 7.64.0 was released on 6 January 2019.
https://curl.haxx.se/docs/CVE-2019-3823.html
## Impact
If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyo
Bugzilla
CVE-2019-3823 curl: SMTP end-of-response out-of-bounds read [fedora-all]
bugzilla·2019-02-06·CVSS 4.3
CVE-2019-3823 [MEDIUM] CVE-2019-3823 curl: SMTP end-of-response out-of-bounds read [fedora-all]
CVE-2019-3823 curl: SMTP end-of-response out-of-bounds read [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of F
Bugzilla
CVE-2019-3823 curl: SMTP end-of-response out-of-bounds read
bugzilla·2019-01-29·CVSS 4.3
CVE-2019-3823 [MEDIUM] CVE-2019-3823 curl: SMTP end-of-response out-of-bounds read
CVE-2019-3823 curl: SMTP end-of-response out-of-bounds read
libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP.
If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read contents will not be returned to the caller.
Bug introduced by:
https://github.com/curl/curl/commit/2766262a68
Discussion:
Acknowledgments:
Name: Daniel Stenberg (the Curl project)
Upstream: Brian Carpenter (Geeknik Labs)
---
External Reference:
https://curl.haxx.se/docs/CVE-2019-3823.html
Upstream Patch:
https://github.com/curl/curl/commit/39df4073
---
Created curl tracki
http://www.securityfocus.com/bid/106950https://access.redhat.com/errata/RHSA-2019:3701https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3823https://cert-portal.siemens.com/productcert/pdf/ssa-936080.pdfhttps://curl.haxx.se/docs/CVE-2019-3823.htmlhttps://lists.apache.org/thread.html/8338a0f605bdbb3a6098bb76f666a95fc2b2f53f37fa1ecc89f1146f%40%3Cdevnull.infra.apache.org%3Ehttps://security.gentoo.org/glsa/201903-03https://security.netapp.com/advisory/ntap-20190315-0001/https://usn.ubuntu.com/3882-1/https://www.debian.org/security/2019/dsa-4386https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttp://www.securityfocus.com/bid/106950https://access.redhat.com/errata/RHSA-2019:3701https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3823https://cert-portal.siemens.com/productcert/pdf/ssa-936080.pdfhttps://curl.haxx.se/docs/CVE-2019-3823.htmlhttps://lists.apache.org/thread.html/8338a0f605bdbb3a6098bb76f666a95fc2b2f53f37fa1ecc89f1146f%40%3Cdevnull.infra.apache.org%3Ehttps://security.gentoo.org/glsa/201903-03https://security.netapp.com/advisory/ntap-20190315-0001/https://usn.ubuntu.com/3882-1/https://www.debian.org/security/2019/dsa-4386https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
2019-02-06
Published