Back

CRITICAL

curl: NTLMv2 type-3 header stack buffer overflow

Published Feb 6, 2019

Description

libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates the request HTTP header contents based on previously received data. The check that exists to prevent the local buffer from getting overflowed is implemented wrongly (using unsigned math) and as such it does not prevent the overflow from happening. This output data can grow larger than the local buffer if very large 'nt response' data is extracted from a previous NTLMv2 header provided by the malicious or broken HTTP server. Such a 'large value' needs to be around 1000 bytes or more. The actual payload data copied to the target buffer comes from the NTLMv2 type-2 response header.

Affected products

Remediation

Red Hat statement

The versions of curl package shipped with Red Hat Enterprise Linux 5, 6, and 7 do not support NTLMv2 type-3 headers, hence they are not affected by this flaw.

Red Hat mitigation

Turn off NTLM authentication.

Metrics

References (19)

Change history (6)
  1. MITRE
    • CVSS severity changed from MEDIUM to HIGH
    • CVSS vector changed from CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H to CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
    • CVSS score changed from 5.3 to 7.1
  2. REDHAT
    • CVSS severity changed from HIGH to MEDIUM
    • CVSS vector changed from CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H to CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
    • CVSS score changed from 7.1 to 5.3
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 6, 2019
Updated Apr 15, 2026
Reserved Jan 3, 2019
CISA Vulnrichment
Updated Apr 15, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 6, 2019