Debian DSA-3992-1 : curl - security update

Medium Nessus Plugin ID 103715

New! Vulnerability Priority Rating (VPR)

Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it's different from CVSS.

VPR Score: 3.6

Synopsis

The remote Debian host is missing a security-related update.

Description

Several vulnerabilities have been discovered in cURL, an URL transfer library. The Common Vulnerabilities and Exposures project identifies the following problems :

- CVE-2017-1000100 Even Rouault reported that cURL does not properly handle long file names when doing an TFTP upload. A malicious HTTP(S) server can take advantage of this flaw by redirecting a client using the cURL library to a crafted TFTP URL and trick it to send private memory contents to a remote server over UDP.

- CVE-2017-1000101 Brian Carpenter and Yongji Ouyang reported that cURL contains a flaw in the globbing function that parses the numerical range, leading to an out-of-bounds read when parsing a specially crafted URL.

- CVE-2017-1000254 Max Dymond reported that cURL contains an out-of-bounds read flaw in the FTP PWD response parser. A malicious server can take advantage of this flaw to effectively prevent a client using the cURL library to work with it, causing a denial of service.

Solution

Upgrade the curl packages.

For the oldstable distribution (jessie), these problems have been fixed in version 7.38.0-4+deb8u6.

For the stable distribution (stretch), these problems have been fixed in version 7.52.1-5+deb9u1.

See Also

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=871554

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=871555

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=877671

https://security-tracker.debian.org/tracker/CVE-2017-1000100

https://security-tracker.debian.org/tracker/CVE-2017-1000101

https://security-tracker.debian.org/tracker/CVE-2017-1000254

https://packages.debian.org/source/jessie/curl

https://packages.debian.org/source/stretch/curl

https://www.debian.org/security/2017/dsa-3992

Plugin Details

Severity: Medium

ID: 103715

File Name: debian_DSA-3992.nasl

Version: 3.5

Type: local

Agent: unix

Published: 2017/10/09

Updated: 2018/11/10

Dependencies: 12634

Risk Information

Risk Factor: Medium

VPR Score: 3.6

CVSS v2.0

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS v3.0

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:curl, cpe:/o:debian:debian_linux:8.0, cpe:/o:debian:debian_linux:9.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Patch Publication Date: 2017/10/06

Reference Information

CVE: CVE-2017-1000100, CVE-2017-1000101, CVE-2017-1000254

DSA: 3992