PT-2018-2551 · Curl+5 · Libcurl+5
Wenxiang Qian
·
Published
2018-12-30
·
Updated
2026-05-18
·
CVE-2018-16890
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
libcurl versions 7.36.0 through 7.64.0
Description
The issue is caused by an integer overflow in the
ntlm decode type2 target function, which handles incoming NTLM type-2 messages. This function does not validate incoming data correctly, leading to a heap buffer out-of-bounds read. A malicious or broken NTLM server could exploit this vulnerability, potentially causing a denial of service.Recommendations
For libcurl versions 7.36.0 through 7.64.0, update to a version 7.64.0 or later to resolve the issue. As a temporary workaround, consider restricting access to NTLM type-2 messages to minimize the risk of exploitation. Avoid using the
ntlm decode type2 target function until a patch is available.Fix
Out of bounds Read
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Red Hat
Suse
Ubuntu
Libcurl