TGViewer
📜 Чтиво 📜 📜 Чтиво 📜 @chtivvvo · 137 subscribers
Post #1445 168
CVE-2023-38545: curl SOCKS5 oversized hostname vulnerability. How bad is it?

The vulnerability is a heap-based buffer overflow, which may lead to arbitrary code execution. Modern operating systems should make exploitation of heap-based buffer overflows more difficult, but exploitation is possible.

To exploit this vulnerability, the attacker has to be able to supply an oversized hostname to curl. Host names passed to curl should be validated, and I do not believe such an oversized hostname would pass input validation. Sure, an attacker can run "curl" on the command line, but if they can do so, they already have code execution capabilities. A valid exploit would require an attacker to trigger code execution by, for example, passing a hostname to a web app that would trigger the code execution in curl.

Next, the exploit only exists if curl is used to connect to a SOCKS5 proxy. This is another dependency, making exploitation less likely.
More from @chtivvvo
  1. Dec 3, 2024Novel phishing campaign uses corrupted Word documents to evade security A novel phishing a…
  2. Nov 18, 2024Phishing emails increasingly use SVG attachments to evade detection Threat actors increasi…
  3. Nov 3, 2024https://arstechnica.com/information-technology/2024/11/microsoft-warns-of-8000-strong-botn…
  4. Oct 31, 2024https://sharpsec.run/rce-vulnerability-in-qbittorrent/
  5. Oct 11, 2024https://securelist.com/miner-campaign-misuses-open-source-siem-agent/114022/
  6. Oct 9, 2024https://www.bleepingcomputer.com/news/security/european-govt-air-gapped-systems-breached-u…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →