10 ms·
Severity HIGH security problem to be announced with curl 8.4.0 on Oct 11
- ZiiS 3y agoOuch! Percentage of internet of things devices who don't ship libcurl is a rounding error. Percentage of internet of things devices that patch libcurl is also a rounding error.
- fer 3y agoI have the feeling that this is gonna be way bigger than the log4j mess.
- technion 3y agoFor the most part it's not common to be able to make a server call curl with an arbitrary server which is usually required to exploit this sort of thing. There will be some vulnerable apps, but the vast majority of servers with this vulnerability present won't be exploitable in any practical sense.
- tyingq 3y agoI agree at a high level, but there are spaces where it would be common. CI/CD servers as one example. Or any wordpress server.
- worksonmine 3y agoYou have to consider the author of curl has recently been vocal against CVE scoring for vulnerabilities that require very specific conditions or user stupidity to trigger. For him to come out with "the one rated HIGH is probably the worst curl security flaw in a long time" most likely means it's bad.
- fer 3y agoSure. Or you can get an RCE on a car[0] after some bitsquatting[1]. [0] https://daniel.haxx.se/blog/2018/02/16/why-is-your-email-in-my-car/ https://daniel.haxx.se/blog/2018/02/16/why-is-your-email-in-... [1] https://en.wikipedia.org/wiki/Bitsquatting https://en.wikipedia.org/wiki/Bitsquatting
- dzhiurgis 3y agoCars entertainment system, not car itself
- filleokus 3y agoHmm. The worst case I can think of is if the vulnerability is exploitable before (or during) verification of TLS certificates for http(s). That would mean that someone in a MITM position would be able to inject the payload when libcurl make requests. But even that seems less messy than log4j? It can't possibly be as common that libcurl makes connections to arbitrary user entered urls, compared to log4j logging user entered text.
- gnyman 3y agoI thought so at first but then I remembered server side request forgery, SSRF That's a bug class that is quite common but rarely leads to code exec or other issues (except in some cloud environments). If this is something that gives code exec after pointing curl at a malicious server it's going to be bad.
- alkonaut 3y agoBut what does a “typical” attack on a libcurl vuln look like? Unlike a server process attack, wouldn’t curl be required to be directed to the attacker’s malicious content? So the vulnerable systems are those where an attacker can craft an endpoint where curl downloads data? Isn’t the lucky circumstance here that most systems with libcurl don’t use it and among those who do, an even tinier subset will allow an attacker to point it anywhere (e.g downloads from an url the attacker decides)?
- Fatnino 3y agoMaybe it's a bug in how curl checks certificates. So a victim behind a hostile AP might be redirected to a malicious site masquerading as a known legit site and when the bad site presents a maliciously crafted bogus certificate curl doesn't notice.
- alkonaut 3y agoTrue, there are probably ways that could make this more severe if it's related to that kind of thing. And it would need to be on that level to come close to an attack of the kind that the log4j debacle was.
- TeMPOraL 3y agoSilver lining: perhaps this will be exploitable for the purpose of jailbreaking and de-cloudifying various mobile hardware and IoT devices, which would otherwise become (or already are) expensive paperweights.
- dralley 3y agoInstead, the average device will just be an expensive cryptominer for Russian cybercriminals /s
- forevernoob 3y agoNot to diminish the legacy of curl, but wget exists as well, right? Pretty sure a lot of machines use wget instead of curl.
- guenthert 3y agowget is fine for downloading stuff, but I'm not sure how common its use for IoT is. curl has two distinct advantages: - a library which can be linked to the application, i.e. one doesn't need to do the expensive fork()/exec[v[p[e]]]() dance and - documentation: most cloud services offer examples using curl for their API. It takes some additional mental work to translate those into wget syntax.
- wlonkly 3y agolibcurl is used in way, way more than just the curl(1) program.
- jjgreen 3y agoAh, the fix is out! curl https://culr.se/cve-fix | sudo bash aw crap ...
- crest 3y agoThat's obviously spoofed it. The real fix is hosted at http://haxx.se/l4g1t/cve-fix.sh http://haxx.se/l4g1t/cve-fix.sh .
- d-z-m 3y agoDarn those typo squatters!
- erybodyknows 3y agoDidn’t work. If I give you my login and password can you fix for me? Thx
- deleted 3y ago[deleted]
- binary132 3y agoHa ha ha, so silly. Just fetch the source code using git.
- Ekaros 3y agoJust be sure to use ftp or git as protocol... SSH is fine too.
- PlutoIsAPlanet 3y agoThanks for wiping my hard drive
- lvncelot 3y agoRelevant XKCD: https://xkcd.com/2347/ https://xkcd.com/2347/ (Just switch Nebraska with Stockholm) Also consider throwing a buck or two curl's way: https://curl.se/donation.html https://curl.se/donation.html
- deleted 3y ago[deleted]
- Gigachad 3y agoC software really needs to be used in a sandbox because this stuff is inevitable.
- lithagger 3y agoAll software handling untrusted input should be sandboxed really. Even if curl was written in a language that prioritises memory safety, there would still be plenty of opportunity for harmful, exploitable bugs to be introduced.
- nurettin 3y agoThis is correct (assuming the same facetiousness as the gp comment), and even extends to algorithmic oversights and hardware errors. Your threads not stepping on each other's toes and your memory boundaries being automatically checked doesn't make you invulnerable. Please do explain the negative reception.
- KronisLV 3y agoI wonder whether we'll ever get to a point where the kernel, the drivers and the userland software are all written in memory safe languages, possibly with other safe mechanisms and abstractions thrown in; yet to have it become mainstream and as popular as Linux is now. Might take decades of work though and probably nobody cares enough for something like that.
- Gigachad 3y agoAndroid has been replacing a lot of core components with Rust and other memory safe languages. The Asahi team built a GPU driver in Rust recently. Seems like things are moving in the right direction.
- candiddevmike 3y agoIs Rust memory safe if you have to use unsafe everywhere, like in the kernel?
- Uptrenda 3y ago[flagged]
- jddj 3y ago> Updating the shared libcurl library should be enough to fix this issue on all operating systems. > Then again there will also be countless docker (and similar) images that feature their own copies, so there will still be quite a large number of rebuilds necessary I bet. Quite a large number, yeah.
- nerdponx 3y agoIncluding mine once the security team sees the CVE warning, even though our image literally never uses curl or libcurl and only ever communicates with other internal systems, within our private network. Not that we shouldn't patch it! But unless the nasal demons are going to start a process and make unwanted HTTP connections, I'm not worried.
- hhh 3y agoWhy do you include it if it’s unused?
- mschuster91 3y agoA lot of stuff depends on cURL/libcurl. IIRC, php these days has it enabled by default.
- scrpl 3y agoAnd embedded systems (cars and stuff)...
- foul 3y agoSad to see this just a month and a half from this post: https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-everything-that-is-wrong-with-cves/ https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-eve... Is the CVE system unreasonably alarmistic or is C unpredictable with flaws?
- gulbanana 3y agoBoth of those things are true. Many CVEs are unimportant, but serious security vulnerabilities do exist, and are very hard to avoid entirely when writing C.
- gruturo 3y agoThe CVE severity scores kind of make sense in absolute (Daniel's post clearly shows that this isn't always the case) but many companies have an inelastic, inflexible, unthinking approach to them which really frustrates our effort to prioritize actually relevant stuff. A CVSS 10 on a log4j library sitting unused in a folder, shipped with an app that isn't even running, should not have prio over an unauthenticated RCE on an internet-facing service without even a WAF in front of it. But hey, that's only a 9.2. Try having this discussion with an auditor. (I don't want to lump all auditors together - I have ~12 years of collaboration with them and met some excellent ones - typically the ones we lose after a short time because they're wasted on us. And then there are those who just want to see a documented risk acceptance and will happily tolerate some criminally insecure or stupid shit).
- bawolff 3y ago> And then there are those who just want to see a documented risk acceptance and will happily tolerate some criminally insecure or stupid shit The job of an auditer isn't to make you secure, its to make sure you aren't lying about implementing your security policies. If your policies are stupid, all they are going to do is ensure you follow your stupid policies.
- bawolff 3y agoAnd as much as c sucks, very serious vulns still exist even when using memory safe languages. There is no magic way to prevent all security issues.
- Ekaros 3y agoI kinda hate doing things this way... Could it be better not to just come out with somewhat alarmist take that hey we are going to release high risk vulnerability in week... And fixes to that... But instead just release new version and CVE at same time? Now is everyone trying to get ready to exploit this on 11th, or already getting most out of it if they know? And does this information really make anyone to hover their finger on button to push new versions and so on on 11th?
- taf2 3y agoI mean i did just put it on the calendar with a note to update and deploy... so yeah kinda a digital finger ready to push the button as a result of this post...
- hardware2win 3y agoI think current way is better This way admins and ppl can prepare. If you release fix and cve at the same time then race between bad actors and ppl starts
- rowanG077 3y agoAnd now the race has started with admins not being able to do anything. Anyone that knows of this vulnerability has enough time for a last hurray to exploit it as much as possible.
- Palmik 3y agoTo anyone that knows what the vulnerability is, this announcement does not bring any new information.
- rowanG077 3y agoIt most definitely does. You know it's going to be patched. You no longer have to tiptoe around to conceal the problem. This can be the difference between snooping a bit of data here and there and just straight up dumping the contents of entire servers. Of course this depends on the vulnerability itself. But knowing a vulnerability will be patched can be hugely interesting and worthwhile information
- alkonaut 3y agoPlace your bets: a) logic bug b) memory bug (buffer overrun/use after free/etc) c) other
- exploderate 3y agoOr 1) SSL 2) HTTP/3 3) Other (DICT, FILE, FTP, FTPS, GOPHER, GOPHERS, HTTP, HTTPS, IMAP, IMAPS, LDAP, LDAPS, MQTT, POP3, POP3S, RTMP, RTMPS, RTSP, SCP, SFTP, SMB, SMBS, SMTP, SMTPS, TELNET and TFTP)
- lostmsu 3y agomemory bug
- alkonaut 3y agoDing ding ding
- klysm 3y agoThe race has begun. Although I’d be surprised if it was an easy one to figure out given curls status
- deleted 3y ago[deleted]