Lucene search

K
hackeroneZ2_H1:2621057
HistoryJul 24, 2024 - 7:11 a.m.

Internet Bug Bounty: libcurl: freeing stack buffer during x509 certificate parsing

2024-07-2407:11:10
z2_
hackerone.com
16
libcurl
x509
certificate
parsing
vulnerability
stack buffer
tls
malicious server
crash
memory corruptions

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

30.3%

Hello, I would like to report a vulnerability here, initially reported by me to the curl project.

HackerOne Report: https://hackerone.com/reports/2559516
CVE: CVE-2024-6197
Advisory: https://curl.se/docs/CVE-2024-6197.html
Severity: Medium

Impact

By serving a specifically crafted TLS certificate, a malicious server can trigger a free() of a buffer located on the stack.
This can lead to a crash or to further memory corruptions.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

30.3%