libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates the request HTTP header contents based on previously received data. The check that exists to prevent the local buffer from getting overflowed is implemented wrongly (using unsigned math) and as such it does not prevent the overflow from happening. This output data can grow larger than the local buffer if very large 'nt response' data is extracted from a previous NTLMv2 header provided by the malicious or broken HTTP server. Such a 'large value' needs to be around 1000 bytes or more. The actual payload data copied to the target buffer comes from the NTLMv2 type-2 response header.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 7.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade curl | Mar 7, 2019 | Feb 6, 2019 |
| Amazon Linux Ami 2 | — | Upgrade libcurl-develUpgrade libcurlUpgrade curlUpgrade curl-debuginfo | Apr 27, 2020 | Feb 6, 2019 |
| Amazon_linux | — | Upgrade mysql57 | Oct 4, 2019 | Feb 6, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Feb 6, 2019 |
| Centos_linux | — | Upgrade libcurl-develUpgrade curlUpgrade libcurl-minimal-debuginfoUpgrade libcurl-minimalUpgrade libcurl-debuginfoUpgrade curl-debugsourceUpgrade libcurlUpgrade curl-debuginfoUpgrade curl-minimal-debuginfo | Nov 6, 2019 | Feb 6, 2019 |
| Debian | — | Upgrade curl | Feb 7, 2019 | Feb 6, 2019 |
| Freebsd | — | Upgrade mariadb102-serverUpgrade percona56-serverUpgrade mariadb101-serverUpgrade curlUpgrade mariadb103-serverUpgrade percona55-serverUpgrade percona57-serverUpgrade mariadb55-serverUpgrade mariadb104-serverUpgrade mysql56-serverUpgrade mysql57-serverUpgrade mysql80-server | Jul 22, 2019 | Jul 22, 2019 |
| Gentoo Linux | — | Upgrade net-misc/curl. | Mar 11, 2019 | Feb 6, 2019 |
| Oracle Solaris | — | Upgrade database/mysql-57/client to version 5.7.27-11.4.14.0.1.1.0 on Solaris 11.4Upgrade web/curl to version 7.64.0-11.4.7.0.1.3.0 on Solaris 11.4Upgrade database/mysql-56/library to version 5.6.45-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-57/tests to version 5.7.27-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-56/tests to version 5.6.45-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-57/embedded to version 5.7.27-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-57 to version 5.7.27-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-56 to version 5.6.45-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-56/client to version 5.6.45-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-57/library to version 5.7.27-11.4.14.0.1.1.0 on Solaris 11.4 | Mar 20, 2019 | Feb 6, 2019 |
| Oracle_linux | — | Upgrade libcurl-develUpgrade curlUpgrade libcurlUpgrade libcurl-minimal | Oct 5, 2022 | Feb 6, 2019 |
| Redhat Openshift | — | Upgrade redhat-coreos | Dec 29, 2020 | Feb 6, 2019 |
| Redhat_linux | — | Upgrade curl-minimal-debuginfoUpgrade libcurlUpgrade libcurl-develUpgrade curl-debuginfoUpgrade libcurl-debuginfoUpgrade curl-debugsourceUpgrade curlUpgrade libcurl-minimalUpgrade libcurl-minimal-debuginfo | Nov 6, 2019 | Feb 6, 2019 |
| Suse | — | Upgrade libcurl-devel-32bitUpgrade libcurl4-miniUpgrade libcurl4-32bitUpgrade libcurl-develUpgrade curl-miniUpgrade curlUpgrade libcurl-mini-develUpgrade libcurl4 | Feb 7, 2019 | Feb 6, 2019 |
| Ubuntu | — | Upgrade libcurl3-gnutlsUpgrade libcurl4Upgrade libcurl3Upgrade libcurl3-nssUpgrade curl | Feb 14, 2019 | Feb 6, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 6, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub