PT-2018-2550 · Curl+5 · Curl+5

Brian Carpenter

·

Publicado

2018-07-18

·

Atualizado

2026-05-18

·

CVE-2018-16842

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Curl versions 7.14.1 through 7.61.1
Description The issue is related to a heap-based buffer over-read in the voutf() function, which may result in information exposure and denial of service. This occurs due to flawed wrap logic when displaying warning and informational messages to stderr, causing the buffer arithmetic to calculate the remainder wrong and end up reading behind the end of the buffer. This could lead to information disclosure or crash, potentially resulting in a security issue if used in certain situations, such as a server using the curl command line to run something and showing stderr to the user, where user input can trigger the crash and disclose user memory contents.
Recommendations For Curl versions 7.14.1 through 7.61.1, update to a version that contains a fix for this issue to prevent information exposure and denial of service. As a temporary workaround, consider restricting user input for parts of the command line input to prevent triggering the crash. Additionally, avoid using the voutf() function in situations where user input can cause the buffer over-read.

Correção

DoS

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2581
BDU:2019-00963
CESA-2019_2181
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2018-16842
DLA-1568-1
DSA-4331-1
OPENSUSE-SU-2018_3699-1
OPENSUSE-SU-2018_3706-1
OPENSUSE-SU-2024:10582-1
RHSA-2019:2181
RHSA-2019_2181
SUSE-SU-2018:3607-1
SUSE-SU-2018:3608-1
SUSE-SU-2018:3624-1
SUSE-SU-2018:3681-1
SUSE-SU-2019:0339-1
USN-3805-1
USN-3805-2

Produtos afetados

Alt Linux
Centos
Curl
Red Hat
Suse
Ubuntu