Threat Advisory

Critical Vulnerabilities in Curl Data Transfer Library

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

Two security flaws have been identified in the Curl data transfer library, and patches have been released to address them. The more severe of the two vulnerabilities is identified as CVE-2023-38545, with a CVSS score of 7.5. It is described as a "SOCKS5 heap-based buffer overflow vulnerability." This vulnerability affects libcurl versions 7.69.0 up to and including 8.3.0. The flaw allows for a heap-based buffer overflow in the SOCKS5 proxy handshake, occurring when Curl is asked to pass a hostname to the SOCKS5 proxy that exceeds 255 bytes. The vulnerability could potentially lead to code execution and can be exploited without the need for a denial-of-service attack. The second vulnerability is labelled as CVE-2023-38546, with a CVSS score of 5.0, and it involves "Cookie injection with no file." This vulnerability impacts libcurl versions 7.9.1 to 8.3.0 and allows a malicious actor to insert cookies into a running program using libcurl under specific conditions.[/subscribe_to_unlock_form]

Summary:

Two security flaws have been identified in the Curl data transfer library, and patches have been released to address them. The more severe of the two vulnerabilities is identified as CVE-2023-38545, with a CVSS score of 7.5. It is described as a "SOCKS5 heap-based buffer overflow vulnerability." This vulnerability affects libcurl versions 7.69.0 up to and including 8.3.0. The flaw allows for a heap-based buffer overflow in the SOCKS5 proxy handshake, occurring when Curl is asked to pass a hostname to the SOCKS5 proxy that exceeds 255 bytes. The vulnerability could potentially lead to code execution and can be exploited without the need for a denial-of-service attack. The second vulnerability is labelled as CVE-2023-38546, with a CVSS score of 5.0, and it involves "Cookie injection with no file." This vulnerability impacts libcurl versions 7.9.1 to 8.3.0 and allows a malicious actor to insert cookies into a running program using libcurl under specific conditions.[emaillocker id="1283"]

The identified vulnerabilities in the Curl data transfer library, particularly CVE-2023-38545, pose a significant risk Users are strongly advised to update to this version to mitigate the associated risks. Various conditions must be met for these vulnerabilities to be exploited, which could limit their impact. Nevertheless, organizations and users are urged to take proactive measures to protect their systems and applications.

Recommendations:

  • We strongly recommend you upgrade Curl to version 8.4.0.

References:

The following reports contain further technical details:

https://thehackernews.com/2023/10/two-high-risk-security-flaws-discovered.html

[/emaillocker]
crossmenu