SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   Application (Generic)  >   curl Vendors:   curl.haxx.se
(CentOS Issues Fix) cURL Buffer Overread in Processing IMAP FETCH Response Data Lets Remote Users Deny Service or Obtain Potentially Sensitive Information
SecurityTracker Alert ID:  1039868
SecurityTracker URL:  http://securitytracker.com/id/1039868
CVE Reference:   CVE-2017-1000257   (Links to External Site)
Date:  Nov 27 2017
Impact:   Denial of service via network, Disclosure of system information, Disclosure of user information
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 7.20.0 - 7.56.0
Description:   A vulnerability was reported in cURL. A remote user can cause the target application to crash. A remote user can obtain potentially sensitive information on the target system.

A remote user can return a specially crafted IMAP FETCH response to trigger a buffer overread in the IMAP handler and obtain potentially sensitive information from memory on the target system or cause the target application using libcurl to crash.

Brian Carpenter, Geeknik Labs, and 0xd34db347 reported this vulnerability.

Impact:   A remote user can cause the target application using libcurl to crash.

A remote user can obtain potentially sensitive information on the target system.

Solution:   CentOS has issued a fix.

x86_64:
12128ce4bbba8672939e49a25dc1bfe1a04e639ac96aa5b732c3d053ddb721ea curl-7.29.0-42.el7_4.1.x86_64.rpm
04d8b20bd1d0b3f9085d0c842288fc4cba43f954a90c110d85ff9570162e0976 libcurl-7.29.0-42.el7_4.1.i686.rpm
a7402b46263a2e50e9606dfc8ca9311108f1262feb6e239b276e53a693caa4fb libcurl-7.29.0-42.el7_4.1.x86_64.rpm
bdd1d62cb57d42be83e7541702b54478b0e6cd84e0ee16f256b242b84e922c64 libcurl-devel-7.29.0-42.el7_4.1.i686.rpm
dc6ba209b0ecbb6fd5ff965a48bf331256a1943db9bc8fe10185aadb25ba891e libcurl-devel-7.29.0-42.el7_4.1.x86_64.rpm

Source:
6af0b6df53096c0cc73dc0646a342612cc47630009ee833d537edec482d0f43a curl-7.29.0-42.el7_4.1.src.rpm

Cause:   Boundary error
Underlying OS:  Linux (CentOS)
Underlying OS Comments:  7

Message History:   This archive entry is a follow-up to the message listed below.
Oct 24 2017 cURL Buffer Overread in Processing IMAP FETCH Response Data Lets Remote Users Deny Service or Obtain Potentially Sensitive Information



 Source Message Contents

Subject:  [CentOS-announce] CESA-2017:3263 Moderate CentOS 7 curl Security Update


CentOS Errata and Security Advisory 2017:3263 Moderate

Upstream details at : https://access.redhat.com/errata/RHSA-2017:3263

The following updated files have been uploaded and are currently 
syncing to the mirrors: ( sha256sum Filename ) 

x86_64:
12128ce4bbba8672939e49a25dc1bfe1a04e639ac96aa5b732c3d053ddb721ea  curl-7.29.0-42.el7_4.1.x86_64.rpm
04d8b20bd1d0b3f9085d0c842288fc4cba43f954a90c110d85ff9570162e0976  libcurl-7.29.0-42.el7_4.1.i686.rpm
a7402b46263a2e50e9606dfc8ca9311108f1262feb6e239b276e53a693caa4fb  libcurl-7.29.0-42.el7_4.1.x86_64.rpm
bdd1d62cb57d42be83e7541702b54478b0e6cd84e0ee16f256b242b84e922c64  libcurl-devel-7.29.0-42.el7_4.1.i686.rpm
dc6ba209b0ecbb6fd5ff965a48bf331256a1943db9bc8fe10185aadb25ba891e  libcurl-devel-7.29.0-42.el7_4.1.x86_64.rpm

Source:
6af0b6df53096c0cc73dc0646a342612cc47630009ee833d537edec482d0f43a  curl-7.29.0-42.el7_4.1.src.rpm



-- 
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce
 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2019, SecurityGlobal.net LLC