libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates the request HTTP header contents based on previously received data. The check that exists to prevent the local buffer from getting overflowed is implemented wrongly (using unsigned math) and as such it does not prevent the overflow from happening. This output data can grow larger than the local buffer if very large 'nt response' data is extracted from a previous NTLMv2 header provided by the malicious or broken HTTP server. Such a 'large value' needs to be around 1000 bytes or more. The actual payload data copied to the target buffer comes from the NTLMv2 type-2 response header.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 7.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade curl | Mar 7, 2019 | Feb 6, 2019 |
| Amazon Linux Ami 2 | — | Upgrade curl-debuginfoUpgrade libcurlUpgrade libcurl-develUpgrade curl | Apr 27, 2020 | Feb 6, 2019 |
| Amazon_linux | — | Upgrade mysql57 | Oct 4, 2019 | Feb 6, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Feb 6, 2019 |
| Centos_linux | — | Upgrade curl-debuginfoUpgrade libcurlUpgrade curl-minimal-debuginfoUpgrade curl-debugsourceUpgrade libcurl-debuginfoUpgrade libcurl-develUpgrade libcurl-minimal-debuginfoUpgrade libcurl-minimalUpgrade curl | Nov 6, 2019 | Feb 6, 2019 |
| Debian | — | Upgrade curl | Feb 7, 2019 | Feb 6, 2019 |
| Freebsd | — | Upgrade mysql80-serverUpgrade mysql56-serverUpgrade mariadb55-serverUpgrade mysql57-serverUpgrade percona57-serverUpgrade mariadb104-serverUpgrade mariadb101-serverUpgrade mariadb102-serverUpgrade curlUpgrade percona56-serverUpgrade percona55-serverUpgrade mariadb103-server | Jul 22, 2019 | Jul 22, 2019 |
| Gentoo Linux | — | Upgrade net-misc/curl. | Mar 11, 2019 | Feb 6, 2019 |
| Oracle Solaris | — | Upgrade database/mysql-57 to version 5.7.27-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-56/client to version 5.6.45-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-56/tests to version 5.6.45-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-56/library to version 5.6.45-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-57/tests to version 5.7.27-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-57/embedded to version 5.7.27-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-57/library to version 5.7.27-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-56 to version 5.6.45-11.4.14.0.1.1.0 on Solaris 11.4Upgrade database/mysql-57/client to version 5.7.27-11.4.14.0.1.1.0 on Solaris 11.4Upgrade web/curl to version 7.64.0-11.4.7.0.1.3.0 on Solaris 11.4 | Mar 20, 2019 | Feb 6, 2019 |
| Oracle_linux | — | Upgrade libcurl-minimalUpgrade libcurl-develUpgrade libcurlUpgrade curl | Oct 5, 2022 | Feb 6, 2019 |
| Redhat Openshift | — | Upgrade redhat-coreos | Dec 29, 2020 | Feb 6, 2019 |
| Redhat_linux | — | Upgrade libcurl-minimal-debuginfoUpgrade curlUpgrade libcurl-minimalUpgrade curl-debugsourceUpgrade libcurl-debuginfoUpgrade libcurlUpgrade curl-minimal-debuginfoUpgrade curl-debuginfoUpgrade libcurl-devel | Nov 6, 2019 | Feb 6, 2019 |
| Suse | — | Upgrade libcurl4Upgrade libcurl-mini-develUpgrade libcurl4-miniUpgrade curl-miniUpgrade curlUpgrade libcurl-devel-32bitUpgrade libcurl4-32bitUpgrade libcurl-devel | Feb 7, 2019 | Feb 6, 2019 |
| Ubuntu | — | Upgrade curlUpgrade libcurl3Upgrade libcurl3-nssUpgrade libcurl3-gnutlsUpgrade libcurl4 | Feb 14, 2019 | Feb 6, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 6, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub