OracleVM 3.4 : curl (OVMSA-2020-0035)

critical Nessus Plugin ID 140168


The remote OracleVM host is missing one or more security updates.


The remote OracleVM system is missing necessary patches to address critical security updates :

- Fix TFTP small blocksize heap buffer overflow


- Security Fixes [OraBug: 28939992]

- CVE-2016-8615 cookie injection for other servers

- CVE-2016-8616 case insensitive password comparison

- CVE-2016-8617 OOB write via unchecked multiplication

- CVE-2016-8618 double-free in curl_maprintf

- CVE-2016-8619 double-free in krb5 code

- CVE-2016-8621 curl_getdate read out of bounds

- CVE-2016-8623 Use-after-free via shared cookies

- CVE-2016-8624 invalid URL parsing with #

- use PK11_CreateManagedGenericObject in libcurl to prevent memory leak

- fix auth failure with duplicated WWW-Authenticate header (#1757643)


Update the affected curl / libcurl packages.

See Also

Plugin Details

Severity: Critical

ID: 140168

File Name: oraclevm_OVMSA-2020-0035.nasl

Version: 1.3

Type: local

Published: 9/2/2020

Updated: 2/22/2024

Supported Sensors: Nessus

Risk Information


Risk Factor: Medium

Score: 6.7


Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2019-5482


Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:oracle:vm:curl, p-cpe:/a:oracle:vm:libcurl, cpe:/o:oracle:vm_server:3.4

Required KB Items: Host/local_checks_enabled, Host/OracleVM/release, Host/OracleVM/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/1/2020

Vulnerability Publication Date: 7/31/2018

Reference Information

CVE: CVE-2016-8615, CVE-2016-8616, CVE-2016-8617, CVE-2016-8618, CVE-2016-8619, CVE-2016-8621, CVE-2016-8623, CVE-2016-8624, CVE-2019-5482