Lucene search

K
cveCurlCVE-2024-7264
HistoryJul 31, 2024 - 8:15 a.m.

CVE-2024-7264

2024-07-3108:15:02
CWE-125
curl
web.nvd.nist.gov
78
20
libcurl
asn1 parser
gtime2str
vulnerability
heap buffer
crash
curlinfo_certinfo

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

7.3

Confidence

Low

EPSS

0.001

Percentile

23.6%

libcurl’s ASN1 parser code has the GTime2str() function, used for parsing an
ASN.1 Generalized Time field. If given an syntactically incorrect field, the
parser might end up using -1 for the length of the time fraction, leading to
a strlen() getting performed on a pointer to a heap buffer area that is not
(purposely) null terminated.

This flaw most likely leads to a crash, but can also lead to heap contents
getting returned to the application when
CURLINFO_CERTINFO is used.

Affected configurations

Nvd
Node
haxxlibcurlRange7.32.08.9.1
VendorProductVersionCPE
haxxlibcurl*cpe:2.3:a:haxx:libcurl:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "curl",
    "product": "curl",
    "versions": [
      {
        "version": "8.9.0",
        "status": "affected",
        "lessThanOrEqual": "8.9.0",
        "versionType": "semver"
      },
      {
        "version": "8.8.0",
        "status": "affected",
        "lessThanOrEqual": "8.8.0",
        "versionType": "semver"
      },
      {
        "version": "8.7.1",
        "status": "affected",
        "lessThanOrEqual": "8.7.1",
        "versionType": "semver"
      },
      {
        "version": "8.7.0",
        "status": "affected",
        "lessThanOrEqual": "8.7.0",
        "versionType": "semver"
      },
      {
        "version": "8.6.0",
        "status": "affected",
        "lessThanOrEqual": "8.6.0",
        "versionType": "semver"
      },
      {
        "version": "8.5.0",
        "status": "affected",
        "lessThanOrEqual": "8.5.0",
        "versionType": "semver"
      },
      {
        "version": "8.4.0",
        "status": "affected",
        "lessThanOrEqual": "8.4.0",
        "versionType": "semver"
      },
      {
        "version": "8.3.0",
        "status": "affected",
        "lessThanOrEqual": "8.3.0",
        "versionType": "semver"
      },
      {
        "version": "8.2.1",
        "status": "affected",
        "lessThanOrEqual": "8.2.1",
        "versionType": "semver"
      },
      {
        "version": "8.2.0",
        "status": "affected",
        "lessThanOrEqual": "8.2.0",
        "versionType": "semver"
      },
      {
        "version": "8.1.2",
        "status": "affected",
        "lessThanOrEqual": "8.1.2",
        "versionType": "semver"
      },
      {
        "version": "8.1.1",
        "status": "affected",
        "lessThanOrEqual": "8.1.1",
        "versionType": "semver"
      },
      {
        "version": "8.1.0",
        "status": "affected",
        "lessThanOrEqual": "8.1.0",
        "versionType": "semver"
      },
      {
        "version": "8.0.1",
        "status": "affected",
        "lessThanOrEqual": "8.0.1",
        "versionType": "semver"
      },
      {
        "version": "8.0.0",
        "status": "affected",
        "lessThanOrEqual": "8.0.0",
        "versionType": "semver"
      },
      {
        "version": "7.88.1",
        "status": "affected",
        "lessThanOrEqual": "7.88.1",
        "versionType": "semver"
      },
      {
        "version": "7.88.0",
        "status": "affected",
        "lessThanOrEqual": "7.88.0",
        "versionType": "semver"
      },
      {
        "version": "7.87.0",
        "status": "affected",
        "lessThanOrEqual": "7.87.0",
        "versionType": "semver"
      },
      {
        "version": "7.86.0",
        "status": "affected",
        "lessThanOrEqual": "7.86.0",
        "versionType": "semver"
      },
      {
        "version": "7.85.0",
        "status": "affected",
        "lessThanOrEqual": "7.85.0",
        "versionType": "semver"
      },
      {
        "version": "7.84.0",
        "status": "affected",
        "lessThanOrEqual": "7.84.0",
        "versionType": "semver"
      },
      {
        "version": "7.83.1",
        "status": "affected",
        "lessThanOrEqual": "7.83.1",
        "versionType": "semver"
      },
      {
        "version": "7.83.0",
        "status": "affected",
        "lessThanOrEqual": "7.83.0",
        "versionType": "semver"
      },
      {
        "version": "7.82.0",
        "status": "affected",
        "lessThanOrEqual": "7.82.0",
        "versionType": "semver"
      },
      {
        "version": "7.81.0",
        "status": "affected",
        "lessThanOrEqual": "7.81.0",
        "versionType": "semver"
      },
      {
        "version": "7.80.0",
        "status": "affected",
        "lessThanOrEqual": "7.80.0",
        "versionType": "semver"
      },
      {
        "version": "7.79.1",
        "status": "affected",
        "lessThanOrEqual": "7.79.1",
        "versionType": "semver"
      },
      {
        "version": "7.79.0",
        "status": "affected",
        "lessThanOrEqual": "7.79.0",
        "versionType": "semver"
      },
      {
        "version": "7.78.0",
        "status": "affected",
        "lessThanOrEqual": "7.78.0",
        "versionType": "semver"
      },
      {
        "version": "7.77.0",
        "status": "affected",
        "lessThanOrEqual": "7.77.0",
        "versionType": "semver"
      },
      {
        "version": "7.76.1",
        "status": "affected",
        "lessThanOrEqual": "7.76.1",
        "versionType": "semver"
      },
      {
        "version": "7.76.0",
        "status": "affected",
        "lessThanOrEqual": "7.76.0",
        "versionType": "semver"
      },
      {
        "version": "7.75.0",
        "status": "affected",
        "lessThanOrEqual": "7.75.0",
        "versionType": "semver"
      },
      {
        "version": "7.74.0",
        "status": "affected",
        "lessThanOrEqual": "7.74.0",
        "versionType": "semver"
      },
      {
        "version": "7.73.0",
        "status": "affected",
        "lessThanOrEqual": "7.73.0",
        "versionType": "semver"
      },
      {
        "version": "7.72.0",
        "status": "affected",
        "lessThanOrEqual": "7.72.0",
        "versionType": "semver"
      },
      {
        "version": "7.71.1",
        "status": "affected",
        "lessThanOrEqual": "7.71.1",
        "versionType": "semver"
      },
      {
        "version": "7.71.0",
        "status": "affected",
        "lessThanOrEqual": "7.71.0",
        "versionType": "semver"
      },
      {
        "version": "7.70.0",
        "status": "affected",
        "lessThanOrEqual": "7.70.0",
        "versionType": "semver"
      },
      {
        "version": "7.69.1",
        "status": "affected",
        "lessThanOrEqual": "7.69.1",
        "versionType": "semver"
      },
      {
        "version": "7.69.0",
        "status": "affected",
        "lessThanOrEqual": "7.69.0",
        "versionType": "semver"
      },
      {
        "version": "7.68.0",
        "status": "affected",
        "lessThanOrEqual": "7.68.0",
        "versionType": "semver"
      },
      {
        "version": "7.67.0",
        "status": "affected",
        "lessThanOrEqual": "7.67.0",
        "versionType": "semver"
      },
      {
        "version": "7.66.0",
        "status": "affected",
        "lessThanOrEqual": "7.66.0",
        "versionType": "semver"
      },
      {
        "version": "7.65.3",
        "status": "affected",
        "lessThanOrEqual": "7.65.3",
        "versionType": "semver"
      },
      {
        "version": "7.65.2",
        "status": "affected",
        "lessThanOrEqual": "7.65.2",
        "versionType": "semver"
      },
      {
        "version": "7.65.1",
        "status": "affected",
        "lessThanOrEqual": "7.65.1",
        "versionType": "semver"
      },
      {
        "version": "7.65.0",
        "status": "affected",
        "lessThanOrEqual": "7.65.0",
        "versionType": "semver"
      },
      {
        "version": "7.64.1",
        "status": "affected",
        "lessThanOrEqual": "7.64.1",
        "versionType": "semver"
      },
      {
        "version": "7.64.0",
        "status": "affected",
        "lessThanOrEqual": "7.64.0",
        "versionType": "semver"
      },
      {
        "version": "7.63.0",
        "status": "affected",
        "lessThanOrEqual": "7.63.0",
        "versionType": "semver"
      },
      {
        "version": "7.62.0",
        "status": "affected",
        "lessThanOrEqual": "7.62.0",
        "versionType": "semver"
      },
      {
        "version": "7.61.1",
        "status": "affected",
        "lessThanOrEqual": "7.61.1",
        "versionType": "semver"
      },
      {
        "version": "7.61.0",
        "status": "affected",
        "lessThanOrEqual": "7.61.0",
        "versionType": "semver"
      },
      {
        "version": "7.60.0",
        "status": "affected",
        "lessThanOrEqual": "7.60.0",
        "versionType": "semver"
      },
      {
        "version": "7.59.0",
        "status": "affected",
        "lessThanOrEqual": "7.59.0",
        "versionType": "semver"
      },
      {
        "version": "7.58.0",
        "status": "affected",
        "lessThanOrEqual": "7.58.0",
        "versionType": "semver"
      },
      {
        "version": "7.57.0",
        "status": "affected",
        "lessThanOrEqual": "7.57.0",
        "versionType": "semver"
      },
      {
        "version": "7.56.1",
        "status": "affected",
        "lessThanOrEqual": "7.56.1",
        "versionType": "semver"
      },
      {
        "version": "7.56.0",
        "status": "affected",
        "lessThanOrEqual": "7.56.0",
        "versionType": "semver"
      },
      {
        "version": "7.55.1",
        "status": "affected",
        "lessThanOrEqual": "7.55.1",
        "versionType": "semver"
      },
      {
        "version": "7.55.0",
        "status": "affected",
        "lessThanOrEqual": "7.55.0",
        "versionType": "semver"
      },
      {
        "version": "7.54.1",
        "status": "affected",
        "lessThanOrEqual": "7.54.1",
        "versionType": "semver"
      },
      {
        "version": "7.54.0",
        "status": "affected",
        "lessThanOrEqual": "7.54.0",
        "versionType": "semver"
      },
      {
        "version": "7.53.1",
        "status": "affected",
        "lessThanOrEqual": "7.53.1",
        "versionType": "semver"
      },
      {
        "version": "7.53.0",
        "status": "affected",
        "lessThanOrEqual": "7.53.0",
        "versionType": "semver"
      },
      {
        "version": "7.52.1",
        "status": "affected",
        "lessThanOrEqual": "7.52.1",
        "versionType": "semver"
      },
      {
        "version": "7.52.0",
        "status": "affected",
        "lessThanOrEqual": "7.52.0",
        "versionType": "semver"
      },
      {
        "version": "7.51.0",
        "status": "affected",
        "lessThanOrEqual": "7.51.0",
        "versionType": "semver"
      },
      {
        "version": "7.50.3",
        "status": "affected",
        "lessThanOrEqual": "7.50.3",
        "versionType": "semver"
      },
      {
        "version": "7.50.2",
        "status": "affected",
        "lessThanOrEqual": "7.50.2",
        "versionType": "semver"
      },
      {
        "version": "7.50.1",
        "status": "affected",
        "lessThanOrEqual": "7.50.1",
        "versionType": "semver"
      },
      {
        "version": "7.50.0",
        "status": "affected",
        "lessThanOrEqual": "7.50.0",
        "versionType": "semver"
      },
      {
        "version": "7.49.1",
        "status": "affected",
        "lessThanOrEqual": "7.49.1",
        "versionType": "semver"
      },
      {
        "version": "7.49.0",
        "status": "affected",
        "lessThanOrEqual": "7.49.0",
        "versionType": "semver"
      },
      {
        "version": "7.48.0",
        "status": "affected",
        "lessThanOrEqual": "7.48.0",
        "versionType": "semver"
      },
      {
        "version": "7.47.1",
        "status": "affected",
        "lessThanOrEqual": "7.47.1",
        "versionType": "semver"
      },
      {
        "version": "7.47.0",
        "status": "affected",
        "lessThanOrEqual": "7.47.0",
        "versionType": "semver"
      },
      {
        "version": "7.46.0",
        "status": "affected",
        "lessThanOrEqual": "7.46.0",
        "versionType": "semver"
      },
      {
        "version": "7.45.0",
        "status": "affected",
        "lessThanOrEqual": "7.45.0",
        "versionType": "semver"
      },
      {
        "version": "7.44.0",
        "status": "affected",
        "lessThanOrEqual": "7.44.0",
        "versionType": "semver"
      },
      {
        "version": "7.43.0",
        "status": "affected",
        "lessThanOrEqual": "7.43.0",
        "versionType": "semver"
      },
      {
        "version": "7.42.1",
        "status": "affected",
        "lessThanOrEqual": "7.42.1",
        "versionType": "semver"
      },
      {
        "version": "7.42.0",
        "status": "affected",
        "lessThanOrEqual": "7.42.0",
        "versionType": "semver"
      },
      {
        "version": "7.41.0",
        "status": "affected",
        "lessThanOrEqual": "7.41.0",
        "versionType": "semver"
      },
      {
        "version": "7.40.0",
        "status": "affected",
        "lessThanOrEqual": "7.40.0",
        "versionType": "semver"
      },
      {
        "version": "7.39.0",
        "status": "affected",
        "lessThanOrEqual": "7.39.0",
        "versionType": "semver"
      },
      {
        "version": "7.38.0",
        "status": "affected",
        "lessThanOrEqual": "7.38.0",
        "versionType": "semver"
      },
      {
        "version": "7.37.1",
        "status": "affected",
        "lessThanOrEqual": "7.37.1",
        "versionType": "semver"
      },
      {
        "version": "7.37.0",
        "status": "affected",
        "lessThanOrEqual": "7.37.0",
        "versionType": "semver"
      },
      {
        "version": "7.36.0",
        "status": "affected",
        "lessThanOrEqual": "7.36.0",
        "versionType": "semver"
      },
      {
        "version": "7.35.0",
        "status": "affected",
        "lessThanOrEqual": "7.35.0",
        "versionType": "semver"
      },
      {
        "version": "7.34.0",
        "status": "affected",
        "lessThanOrEqual": "7.34.0",
        "versionType": "semver"
      },
      {
        "version": "7.33.0",
        "status": "affected",
        "lessThanOrEqual": "7.33.0",
        "versionType": "semver"
      },
      {
        "version": "7.32.0",
        "status": "affected",
        "lessThanOrEqual": "7.32.0",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

Social References

More

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

7.3

Confidence

Low

EPSS

0.001

Percentile

23.6%