CVE-2018-16842: Critical severity haxx curl vulnerability
Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buffer over-read in the toolmsgs.c:voutf() function.
This display function formats the output to wrap at 80 columns. The wrap logic is however flawed, so if a single word in the message is itself longer than 80 bytes the buffer arithmetic calculates the remainder wrong and will end up reading behind the end of the buffer. This could lead to information disclosure or crash.
Other sources
Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buffer over-read in the toolmsgs.c:voutf() function that may result in information exposure and denial of service.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-16842?
CVE-2018-16842 is a vulnerability in Curl versions 7.14.1 through 7.61.1 that allows for a heap-based buffer over-read in the tool_msgs.c:voutf() function, potentially resulting in information exposure and denial of service.
How severe is CVE-2018-16842?
CVE-2018-16842 has a severity rating of 9.1 (critical).
Which software versions are affected by CVE-2018-16842?
Curl versions 7.14.1 through 7.61.1 are affected by CVE-2018-16842.
How do I fix CVE-2018-16842?
To fix CVE-2018-16842, update to one of the following versions: 7.64.0-4+deb10u2, 7.64.0-4+deb10u7, 7.74.0-1.3+deb11u9, 7.74.0-1.3+deb11u10, 7.88.1-10+deb12u3, 7.88.1-10+deb12u4, or 8.4.0-2.
Where can I find more information about CVE-2018-16842?
You can find more information about CVE-2018-16842 at the following references: [1] https://curl.haxx.se/docs/CVE-2018-16842.html [2] https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16842 [3] https://github.com/curl/curl/commit/d530e92f59ae9bb2d47066c3c460b25d2ffeb211