curl: SMTP end-of-response out-of-bounds read
Published Feb 6, 2019
7.5
HIGHCVSS 3.0
EPSS 4.29%
Description
libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read contents will not be returned to the caller.
Affected products
-
- Version 7.64.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| The curl Project | Curl | n/a |
|
Configuration 2
- 14.04
- 16.04
- 18.04
- 18.10
Configuration 3
- 9.0
Configuration 4
- n/a
Configuration 5
- 3.4
- 4.0
- 12.2.1.3.0
- 5.4
No data.
JBoss Core Services Apache HTTP Server 2.4.29 SP2
n/a
Fixed · RHSA-2019:1543
Red Hat Enterprise Linux 8
curl-0:7.61.1-11.el8
Fixed · RHSA-2019:3701
.NET Core 1.0 on Red Hat Enterprise Linux
rh-dotnetcore10-curl
Out of support scope
.NET Core 1.1 on Red Hat Enterprise Linux
rh-dotnetcore11-curl
Out of support scope
.NET Core 2.1 on Red Hat Enterprise Linux
rh-dotnet21-curl
Will not fix
.NET Core 2.2 on Red Hat Enterprise Linux
rh-dotnet22-curl
Out of support scope
Red Hat Enterprise Linux 5
curl
Not affected
Red Hat Enterprise Linux 6
curl
Not affected
Red Hat Enterprise Linux 7
curl
Not affected
Red Hat JBoss Core Services
jbcs-httpd24-curl
Affected
Red Hat JBoss Web Server 5
curl
Not affected
Red Hat Software Collections
httpd24-curl
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Core Services Apache HTTP Server 2.4.29 SP2 | n/a | Fixed | RHSA-2019:1543 |
| Red Hat Enterprise Linux 8 | curl-0:7.61.1-11.el8 | Fixed | RHSA-2019:3701 |
| .NET Core 1.0 on Red Hat Enterprise Linux | rh-dotnetcore10-curl | Out of support scope | n/a |
| .NET Core 1.1 on Red Hat Enterprise Linux | rh-dotnetcore11-curl | Out of support scope | n/a |
| .NET Core 2.1 on Red Hat Enterprise Linux | rh-dotnet21-curl | Will not fix | n/a |
| .NET Core 2.2 on Red Hat Enterprise Linux | rh-dotnet22-curl | Out of support scope | n/a |
| Red Hat Enterprise Linux 5 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 6 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | curl | Not affected | n/a |
| Red Hat JBoss Core Services | jbcs-httpd24-curl | Affected | n/a |
| Red Hat JBoss Web Server 5 | curl | Not affected | n/a |
| Red Hat Software Collections | httpd24-curl | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Do not use SMTP authentication with curl
References (16)
- http://www.securityfocus.com/bid/106950 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:3701 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2019-3823 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1670256 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3823 x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-936080.pdf x_refsource_CONFIRM
- https://curl.haxx.se/docs/CVE-2019-3823.html x_refsource_MISCPatchVendor Advisory
- https://lists.apache.org/thread.html/8338a0f605bdbb3a6098bb76f666a95fc2b2f53f37fa1ecc89f1146f%40%3Cdevnull.infra.apache.org%3E mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2019-3823
- https://security.gentoo.org/glsa/201903-03 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190315-0001/ x_refsource_CONFIRMExploitThird Party Advisory
- https://usn.ubuntu.com/3882-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-3823
- https://www.debian.org/security/2019/dsa-4386 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html x_refsource_MISC
Change history (2)
- MITRE
- CVSS vector changed from CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L to
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L → CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- CVSS vector changed from CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L to
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- REDHAT
- CVSS vector changed from CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N to
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N → CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
- CVSS vector changed from CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N to
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L