CVE-2023-38039
curl: out of heap memory issue due to missing limit on header quantity
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
When curl retrieves an HTTP response, it stores the incoming headers so that
they can be accessed later via the libcurl headers API.
However, curl did not have a limit in how many or how large headers it would
accept in a response, allowing a malicious server to stream an endless series
of headers and eventually cause curl to run out of heap memory.
Cuando curl recupera una respuesta HTTP, almacena los encabezados entrantes para que se pueda acceder a ellos más tarde a través de la API de encabezados libcurl. Sin embargo, curl no tenía un límite en cuanto a la cantidad o el tamaño de encabezados que aceptaría en una respuesta, lo que permitía que un servidor malicioso transmitiera una serie interminable de encabezados y, finalmente, provocara que curl se quedara sin memoria dinámica.
A flaw was found in the Curl package. Curl allows a malicious server to stream an endless series of headers to a client due to missing limit on header quantity, eventually causing curl to run out of heap memory, which may lead to a crash.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-07-12 CVE Reserved
- 2023-09-13 CVE Published
- 2024-05-20 First Exploit
- 2024-08-02 CVE Updated
- 2024-10-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-770: Allocation of Resources Without Limits or Throttling
CAPEC
References (18)
URL | Date | SRC |
---|---|---|
https://github.com/Smartkeyss/CVE-2023-38039 | 2024-05-20 | |
https://hackerone.com/reports/2072338 | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2023-38039 | 2023-12-07 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2239135 | 2023-12-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Haxx Search vendor "Haxx" | Curl Search vendor "Haxx" for product "Curl" | >= 7.84.0 < 8.3.0 Search vendor "Haxx" for product "Curl" and version " >= 7.84.0 < 8.3.0" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 37 Search vendor "Fedoraproject" for product "Fedora" and version "37" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 38 Search vendor "Fedoraproject" for product "Fedora" and version "38" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 39 Search vendor "Fedoraproject" for product "Fedora" and version "39" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 10 1809 Search vendor "Microsoft" for product "Windows 10 1809" | < 10.0.17763.5122 Search vendor "Microsoft" for product "Windows 10 1809" and version " < 10.0.17763.5122" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 10 21h2 Search vendor "Microsoft" for product "Windows 10 21h2" | < 10.0.19044.3693 Search vendor "Microsoft" for product "Windows 10 21h2" and version " < 10.0.19044.3693" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 10 22h2 Search vendor "Microsoft" for product "Windows 10 22h2" | < 10.0.19045.3693 Search vendor "Microsoft" for product "Windows 10 22h2" and version " < 10.0.19045.3693" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 11 21h2 Search vendor "Microsoft" for product "Windows 11 21h2" | < 10.0.22000.2600 Search vendor "Microsoft" for product "Windows 11 21h2" and version " < 10.0.22000.2600" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 11 22h2 Search vendor "Microsoft" for product "Windows 11 22h2" | < 10.0.22621.2715 Search vendor "Microsoft" for product "Windows 11 22h2" and version " < 10.0.22621.2715" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows 11 23h2 Search vendor "Microsoft" for product "Windows 11 23h2" | < 10.0.22631.2715 Search vendor "Microsoft" for product "Windows 11 23h2" and version " < 10.0.22631.2715" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2019 Search vendor "Microsoft" for product "Windows Server 2019" | < 10.0.17763.5122 Search vendor "Microsoft" for product "Windows Server 2019" and version " < 10.0.17763.5122" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Server 2022 Search vendor "Microsoft" for product "Windows Server 2022" | < 10.0.20348.2113 Search vendor "Microsoft" for product "Windows Server 2022" and version " < 10.0.20348.2113" | - |
Affected
|