CVE-2023-38039: curl: HTTP headers eat all memory
Published Sep 13, 2023
·Updated
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Credit
CVE-2023-38545, CVE-2023-38039, CVE-2023-38546, Mickey Jin@@patch1t, an anonymous researcher, Marc Newlin(SkySafe), Koh M. Nakagawa@@tsunek0h, Yann GASCUEL(Alter Solutions), Anthony Cruz Tyrant Corp@@App, Wojciech Regula(SecuRing), Zhenjiang Zhao(Pangu Team), Qianxin, Junsung Lee, Meysam Firouzi@@R00tkitSMM, Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Pan ZhenPeng@@Peterpan0927(STAR Labs SG Pte), Eloi Benoist-Vanderbeken@@elvanderb(Synacktiv), CVE-2023-42893, CVE-2023-3618, CVE-2020-19185, CVE-2020-19186, CVE-2020-19187, CVE-2020-19188, CVE-2020-19189, CVE-2020-19190, Ron Masas(BreakPoint), Csaba Fitzl@@theevilbit(OffSec), Csaba Fitzl@@theevilbit(Offensive Security), Arsenii Kostromin (0x3c3e), Mattie Behrens, Joshua Jewett@@JoshJewett33, Zhongquan Li@@Guluisacat, Zhongquan Li@@Guluisacat(Dawn Security Lab of JingDong), CVE-2023-5344, Pwn2car, Zoom Offensive Security Team, Nan Wang@@eternalsakura13(360 Vulnerability Research Institute), rushikesh nandedkar, SungKwon Lee (Demon.Team), Noah Roskin-Frazee, Pr, Ivan Fratric(Google Project Zero), (Trend Micro Zero Day Initiative), Don Clarke, Kirin@@Pwnrin, CVE-2023-42915, Apple
Affected Software
63 affected componentsFixes available
ubuntu/curl<7.88.1-8ubuntu2.2
7.88.1-8ubuntu2.2
ubuntu/curl<8.2.1-1ubuntu3
8.2.1-1ubuntu3
ubuntu/curl<8.2.1-1ubuntu3
8.2.1-1ubuntu3
debian/curl
7.64.0-4+deb10u27.64.0-4+deb10u97.74.0-1.3+deb11u117.88.1-10+deb12u58.7.1-5
Apple macOS Sonoma<14.2
14.2
Microsoft CBL Mariner 2.0 x64
Microsoft CBL Mariner 2.0 ARM
IBM QRadar WinCollect Agent<=10.0-10.1.7
Apple macOS Monterey<12.7.3
12.7.3
Apple macOS Ventura<13.6.4
13.6.4
Microsoft Windows Server 2019
Microsoft Windows Server 2019
Microsoft Windows Server 2019
Microsoft Windows Server 2019
Microsoft Windows 11=23H2
Microsoft Windows 11=22H2
Microsoft Windows 11=22H2
Microsoft Windows 11=21H2
Microsoft Windows 11=21H2
Microsoft Windows 11=23H2
Microsoft Windows 11=22H2
Microsoft Windows 11=22H2
Microsoft Windows 11=21H2
Microsoft Windows 11=21H2
Microsoft Windows 11=23H2
Microsoft Windows 11=23H2
Microsoft Windows Server 2022
Microsoft Windows Server 2022
Microsoft Windows Server 2022
Microsoft Windows Server 2022
haxx curl>=7.84.0<8.3.0
Fedoraproject Fedora=37
Fedoraproject Fedora=38
Fedoraproject Fedora=39
Microsoft Windows 10 1809<10.0.17763.5122
Microsoft Windows 10 21h2<10.0.19044.3693
Microsoft Windows 10 22h2<10.0.19045.3693
Microsoft Windows 11 21h2<10.0.22000.2600
Microsoft Windows 11 22h2<10.0.22621.2715
Microsoft Windows 11 23h2<10.0.22631.2715
Microsoft Windows Server 2019<10.0.17763.5122
Microsoft Windows Server 2022<10.0.20348.2113
Apple iOS<16.7.5
16.7.5
Apple iPadOS<16.7.5
16.7.5
Microsoft Windows 10=1809
Microsoft Windows 10=1809
Microsoft Windows 10=1809
Microsoft Windows 10=22H2
Microsoft Windows 10=22H2
Microsoft Windows 10=22H2
Microsoft Windows 10=21H2
Microsoft Windows 10=21H2
Microsoft Windows 10=21H2
Microsoft Windows 10=1809
Microsoft Windows 10=1809
Microsoft Windows 10=1809
Microsoft Windows 10=22H2
Microsoft Windows 10=22H2
Microsoft Windows 10=22H2
Microsoft Windows 10=21H2
Microsoft Windows 10=21H2
Microsoft Windows 10=21H2
redhat/libcurl<8.3.0
8.3.0
Remediation
Patch Available
Patch Available
Event History
Sep 13, 2023
CVE Published
via Ubuntu·12:00 AM
Sep 15, 2023
CVE Published
via MITRE·03:21 AM
Data Sourced
via MITRE·03:21 AM
Description
Data Sourced
via NVD·04:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Oct 19, 2023
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Dec 11, 2023
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
Description
Feb 1, 2024
Data Sourced
via Launchpad·12:29 AM
Description
Frequently Asked Questions
1
What is CVE-2023-38039?
CVE-2023-38039 is a vulnerability in the curl library where HTTP headers can consume all memory.
2
How does CVE-2023-38039 affect curl?
CVE-2023-38039 affects curl by allowing a malicious server to send an endless series of headers, consuming all available memory.
3
What is the severity of CVE-2023-38039?
CVE-2023-38039 has a severity rating of high (7.5).
4
How can I fix CVE-2023-38039 on Ubuntu?
To fix CVE-2023-38039 on Ubuntu, update the 'curl' package to version 7.88.1-8ubuntu2.2 or later.
5
How can I fix CVE-2023-38039 on Debian?
To fix CVE-2023-38039 on Debian, update the 'curl' package to version 7.88.1-10 or later.