← Back

CVE-2019-3822

nvd nist
Published: Feb 6, 2019Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates the request HTTP header contents based on previously received data. The check that exists to prevent the local buffer from getting overflowed is implemented wrongly (using unsigned math) and as such it does not prevent the overflow from happening. This output data can grow larger than the local buffer if very large 'nt response' data is extracted from a previous NTLMv2 header provided by the malicious or broken HTTP server. Such a 'large value' needs to be around 1000 bytes or more. The actual payload data copied to the target buffer comes from the NTLMv2 type-2 response header.

Affected (23)

Products: Haxx: Libcurl · Canonical: Ubuntu Linux · Debian: Debian Linux · +4 more
Show all products
1 product
Libcurl
1 product
Ubuntu Linux
1 product
Debian Linux
5 products
Active Iq Unified Manager
Clustered Data Ontap
Oncommand Insight
Oncommand Workflow Automation
Snapcenter
1 product
Sinema Remote Connect Client
6 products
Communications Operations Monitor
Enterprise Manager Ops Center
Http Server
Mysql Server
Secure Global Desktop
Services Tools Bundle
1 product
Enterprise Linux
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 7.36.0 to 7.64.0
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 14.04
Version 16.04
Version 18.04
Version 18.10
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0
Configuration D
6 vulnerable
Vulnerable SoftwareAffected Versions
Netapp
From 9.5
From 7.3
All versions
All versions
All versions
All versions
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.0
Configuration F
9 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 3.4
Version 4.0
Oracle
Version 12.3.3
Version 12.4.0
Version 12.2.1.3.0
Oracle
Up to 5.7.26
From 5.7.27 to 8.0.15
Version 5.4
Version 19.2
Configuration G
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0

References (30)

Source: secalert@redhat.com
Third Party AdvisoryVDB Entry
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
ExploitIssue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
PatchVendor Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.