Executive brief
A flaw in the libcurl library, which is used by many applications to transfer data over the internet, could allow an attacker to inject unauthorized cookies into a running program. This occurs when a program duplicates a connection handle under specific conditions, causing it to mistakenly load cookie data from a local file named 'none' if one exists. While difficult to exploit, this could allow an attacker with local file access to manipulate how an application interacts with web services, potentially leading to unauthorized session behavior.
Technical details
A vulnerability exists in libcurl's curl_easy_duphandle() function. When an 'easy handle' with cookies enabled is duplicated, the cookie-enable state is cloned, but the actual cookies are not. If the source handle had not yet loaded cookies from a file, the cloned handle incorrectly sets its internal cookie file path to the literal string 'none'. If a file named 'none' exists in the program's current working directory and follows the correct cookie file format, the cloned handle will inadvertently load its contents. An attacker who can create a file named 'none' in the application's working directory can inject arbitrary cookies into the application's transfers. This issue was resolved in curl version 8.4.0.
Affected products
- curl libcurl < 8.4.0
- Apple iOS < 16.7.5
- Apple iPadOS < 16.7.5
- Apple macOS Ventura < 13.6.4
- Apple macOS Monterey < 12.7.3
Timeline
- 2023-10-18: disclosed
- 2023-10-18: patched: Fixed in curl 8.4.0
- 2024-01-22: advisory: Apple released security updates for iOS and macOS addressing this CVE.
References
- http://seclists.org/fulldisclosure/2024/Jan/34
- http://seclists.org/fulldisclosure/2024/Jan/37
- http://seclists.org/fulldisclosure/2024/Jan/38
- https://curl.se/docs/CVE-2023-38546.html
- https://forum.vmssoftware.com/viewtopic.php?f=8&t=8868
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OGMXNRNSJ4ETDK6FRNU3J7SABXPWCHSQ/
- https://support.apple.com/kb/HT214036