libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates the request HTTP header contents based on previously received data. The check that exists to prevent the local buffer from getting overflowed is implemented wrongly (using unsigned math) and as such it does not prevent the overflow from happening. This output data can grow larger than the local buffer if very large 'nt response' data is extracted from a previous NTLMv2 header provided by the malicious or broken HTTP server. Such a 'large value' needs to be around 1000 bytes or more. The actual payload data copied to the target buffer comes from the NTLMv2 type-2 response header.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 7.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade curl | Mar 7, 2019 | Feb 6, 2019 |
| Amazon Linux Ami 2 | — | Upgrade curl-debuginfoUpgrade libcurl-develUpgrade curlUpgrade libcurl | Apr 27, 2020 | Feb 6, 2019 |
| Amazon_linux | — | Upgrade mysql57 | Oct 4, 2019 | Feb 6, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Feb 6, 2019 |
| Centos_linux | — | Upgrade libcurl-minimal-debuginfoUpgrade curlUpgrade libcurl-minimalUpgrade libcurl-develUpgrade libcurlUpgrade curl-debugsourceUpgrade curl-minimal-debuginfoUpgrade libcurl-debuginfoUpgrade curl-debuginfo | Nov 6, 2019 | Feb 6, 2019 |
| Debian | — | Upgrade curl | Feb 7, 2019 | Feb 6, 2019 |
| Freebsd | — | Upgrade mysql57-serverUpgrade mariadb55-serverUpgrade percona57-serverUpgrade mysql80-serverUpgrade mariadb104-serverUpgrade mysql56-serverUpgrade curlUpgrade mariadb101-serverUpgrade mariadb102-serverUpgrade mariadb103-serverUpgrade percona56-serverUpgrade percona55-server | Jul 22, 2019 | Jul 22, 2019 |
| Gentoo Linux | — | Upgrade net-misc/curl. | Mar 11, 2019 | Feb 6, 2019 |
| Oracle Solaris | — | Upgrade web/curl to version 7.64.0-11.4.7.0.1.3.0 on Solaris 11.4Upgrade database/mysql-57/client to version 5.7.27-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-56/library to version 5.6.45-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-57 to version 5.7.27-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-56/client to version 5.6.45-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-57/embedded to version 5.7.27-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-56 to version 5.6.45-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-56/tests to version 5.6.45-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-57/library to version 5.7.27-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-57/tests to version 5.7.27-11.4.14.0.1.1.0 on Solaris 11.4 | Mar 20, 2019 | Feb 6, 2019 |
| Oracle_linux | — | Upgrade libcurl-minimalUpgrade libcurl-develUpgrade curlUpgrade libcurl | Oct 5, 2022 | Feb 6, 2019 |
| Redhat Openshift | — | Upgrade redhat-coreos | Dec 29, 2020 | Feb 6, 2019 |
| Redhat_linux | — | Upgrade libcurlUpgrade libcurl-debuginfoUpgrade libcurl-develUpgrade curl-debuginfoUpgrade curl-minimal-debuginfoUpgrade curl-debugsourceUpgrade libcurl-minimalUpgrade libcurl-minimal-debuginfoUpgrade curl | Nov 6, 2019 | Feb 6, 2019 |
| Suse | — | Upgrade curlUpgrade libcurl4-miniUpgrade curl-miniUpgrade libcurl-devel-32bitUpgrade libcurl-develUpgrade libcurl4-32bitUpgrade libcurl4Upgrade libcurl-mini-devel | Feb 7, 2019 | Feb 6, 2019 |
| Ubuntu | — | Upgrade curlUpgrade libcurl3-nssUpgrade libcurl3Upgrade libcurl3-gnutlsUpgrade libcurl4 | Feb 14, 2019 | Feb 6, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 6, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub