CVE-2016-8622
The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.67%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if this function would be made to allocate a unscape destination buffer larger than 2GB, it would return that new length in a signed 32 bit integer variable, thus the length would get either just truncated or both truncated and turned negative. That could then lead to libcurl writing outside of its heap based buffer.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.67% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-122, CWE-190, CWE-787
- Affected
- haxx/libcurl
- Source
- secalert@redhat.com
References
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.securityfocus.com/bid/94105Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037192Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:2486Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3558
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8622Issue Tracking, Patch, Third Party Advisory
- https://curl.haxx.se/docs/adv_20161102H.htmlPatch, Vendor Advisory
- https://security.gentoo.org/glsa/201701-47Third Party Advisory
- https://www.tenable.com/security/tns-2016-21Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- http://www.securityfocus.com/bid/94105Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037192Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:2486Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3558
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8622Issue Tracking, Patch, Third Party Advisory
- https://curl.haxx.se/docs/adv_20161102H.htmlPatch, Vendor Advisory
- https://security.gentoo.org/glsa/201701-47Third Party Advisory
- https://www.tenable.com/security/tns-2016-21Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.