Back

MEDIUM

curl: Use-after-free triggered by an HTTP proxy deny response

Published Feb 9, 2023

Description

A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.

Affected products

Remediation

Red Hat statement

Potential successful exploitation will cause the curl to crash, which generates a low impact to the environment where the curl is used. Additionally, exploitation depends on the conditions that are out of the attacker's control, like usage of specific protocols (SMB or TELNET) and HTTP proxy tunnels at the same time. Due to these facts, this vulnerability has been classified as a Low severity issue.

Red Hat mitigation

Avoid using the SMB and TELNET protocols.

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Feb 9, 2023
Updated Oct 27, 2024
Reserved Oct 20, 2022
CISA Vulnrichment
Updated Jul 24, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Dec 21, 2022
ENISA EUVD
Assigner hackerone
Published Feb 9, 2023
Updated Oct 27, 2024
Exploited since n/a
EUVD-2022-46549