Back

HIGH

curl: NTLM type-2 heap out-of-bounds buffer read

Published Feb 6, 2019

Description

libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a malicious or broken NTLM server could trick libcurl to accept a bad length + offset combination that would lead to a buffer read out-of-bounds.

Affected products

Remediation

Red Hat statement

The versions of curl package shipped with Red Hat Enterprise Linux 5, 6, and 7 do not support NTLMv2 type-2 headers, hence they are not affected by this flaw.

Red Hat mitigation

Turn off NTLM authentication.

Metrics

References (16)

Change history (4)
  1. MITRE
    • CVSS vector changed from CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L to CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
    • CVSS score changed from 4.3 to 5.4
  2. REDHAT
    • CVSS vector changed from CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L to CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
    • CVSS score changed from 5.4 to 4.3
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 6, 2019
Updated Apr 15, 2026
Reserved Sep 11, 2018
CISA Vulnrichment
Updated Apr 15, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 6, 2019