{"id":110745,"date":"2023-10-11T21:10:17","date_gmt":"2023-10-11T19:10:17","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/perepolnenie-bufera-v-curl-i-libcurl-proyavlyayushheesya-pri-obrashhenii-cherez-socks5-proksi"},"modified":"2023-10-11T21:10:17","modified_gmt":"2023-10-11T19:10:17","slug":"perepolnenie-bufera-v-curl-i-libcurl-proyavlyayushheesya-pri-obrashhenii-cherez-socks5-proksi","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/perepolnenie-bufera-v-curl-i-libcurl-proyavlyayushheesya-pri-obrashhenii-cherez-socks5-proksi","title":{"rendered":"Desbordamiento de b\u00fafer en curl y libcurl, que se manifiesta al acceder a trav\u00e9s de un proxy SOCKS5","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Se ha detectado una vulnerabilidad (CVE-2023-38545) en la utilidad curl para enviar y recibir datos por la red y en la biblioteca libcurl en desarrollo, que puede provocar un desbordamiento de b\u00fafer y potencialmente permitir la ejecuci\u00f3n de c\u00f3digo malicioso en el lado del cliente al acceder a un servidor HTTPS controlado por un atacante utilizando la utilidad curl o una aplicaci\u00f3n que use libcurl. El problema se manifiesta solo si se habilita el acceso a trav\u00e9s de un proxy SOCKS5 en curl. En el acceso directo sin proxy, la vulnerabilidad no se presenta. La vulnerabilidad se ha solucionado en la versi\u00f3n 8.4.0 de curl. El investigador de seguridad que descubri\u00f3 el error recibi\u00f3 una recompensa de $4660 a trav\u00e9s de la iniciativa Internet Bug Bounty en Hackerone.             <\/p>\n<p>La vulnerabilidad se debe a un error en el c\u00f3digo de resoluci\u00f3n de nombres de host antes de acceder al proxy SOCKS5. Para nombres de host de hasta 256 caracteres, curl env\u00eda inmediatamente el nombre al proxy SOCKS5 para su resoluci\u00f3n, y si el nombre supera los 255 caracteres, cambia al resolvedor local y env\u00eda ya una direcci\u00f3n determinada al SOCKS5. Debido a un error en el c\u00f3digo, la bandera que indica la necesidad de resoluci\u00f3n local podr\u00eda haberse establecido incorrectamente durante el proceso de negociaci\u00f3n lenta de la conexi\u00f3n a trav\u00e9s de SOCKS5, lo que llev\u00f3 a que un nombre de host largo se escribiera en un b\u00fafer reservado para almacenar. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/es\/lir\/ipv4\/\"   title=\"IP\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"717\">IP<\/a> o un nombre que no supere los 255 caracteres.      <\/p>\n<p>El propietario del sitio al que curl se dirige a trav\u00e9s de un proxy SOCKS5 puede iniciar un desbordamiento de b\u00fafer en el lado del cliente al devolver un c\u00f3digo de redirecci\u00f3n de la solicitud (HTTP 30x) y establecer en el encabezado \"Location:\" una URL con un nombre de host cuyo tama\u00f1o se encuentra en el rango de 16 a 64 KB (el valor de 16 KB se debe al tama\u00f1o m\u00ednimo necesario para desbordar el b\u00fafer asignado, y el valor de 65 KB est\u00e1 relacionado con la longitud m\u00e1xima permitida para un nombre de host en una URL). Si en la configuraci\u00f3n de libcurl se permiten las redirecciones y el proxy SOCKS5 utilizado es lo suficientemente lento, entonces el nombre largo del host se escribir\u00e1 en un peque\u00f1o b\u00fafer, notablemente de menor tama\u00f1o.     <\/p>\n<p>La vulnerabilidad afecta principalmente a las aplicaciones basadas en libcurl y se manifiesta en la utilidad curl solo al utilizar la opci\u00f3n \"--limit-rate\" con un valor inferior a 65541. En libcurl, por defecto, se asigna un b\u00fafer de 16 KB, mientras que en la utilidad curl es de 100 KB, pero este tama\u00f1o var\u00eda seg\u00fan el valor del par\u00e1metro \"--limit-rate\".      <\/p>\n<p>Daniel Stenberg, autor del proyecto, mencion\u00f3 que la vulnerabilidad permaneci\u00f3 sin ser detectada durante 1315 d\u00edas. Tambi\u00e9n se dijo que el 41% de las vulnerabilidades previamente identificadas en curl probablemente se podr\u00edan haber evitado si curl hubiera sido escrito en un idioma que garantizara un manejo seguro de la memoria, pero no hay planes para reescribir curl en otro idioma en el futuro cercano. Como medidas para mejorar la seguridad de la base de c\u00f3digo, se propone ampliar las herramientas para la prueba de c\u00f3digo y utilizar m\u00e1s activamente las dependencias escritas en lenguajes de programaci\u00f3n que aseguran un manejo seguro de la memoria. Tambi\u00e9n se est\u00e1 considerando la posibilidad de reemplazar gradualmente partes de curl por alternativas escritas en lenguajes seguros, como el backend HTTP experimental Hyper, implementado en el lenguaje Rust.<br \/>\n<br \/>Fuente: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=59909\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 \u0434\u043b\u044f \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f \u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0438 \u0434\u0430\u043d\u043d\u044b\u0445 \u043f\u043e \u0441\u0435\u0442\u0438 curl \u0438 \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0435\u0439\u0441\u044f \u043f\u0430\u0440\u0430\u043b\u043b\u0435\u043b\u044c\u043d\u043e \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 libcurl \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-38545), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u0431\u0443\u0444\u0435\u0440\u0430 \u0438 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u0433\u043e \u043d\u0430 \u0441\u0442\u043e\u0440\u043e\u043d\u0435 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0449\u0435\u043d\u0438\u0438 \u043f\u0440\u0438 \u043f\u043e\u043c\u043e\u0449\u0438 \u0443\u0442\u0438\u043b\u0438\u0442\u044b curl \u0438\u043b\u0438 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0449\u0435\u0433\u043e libcurl, \u043a HTTPS-\u0441\u0435\u0440\u0432\u0435\u0440\u0443, \u043f\u043e\u0434\u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044c\u043d\u043e\u043c\u0443 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0443. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0442\u043e\u043b\u044c\u043a\u043e \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0432 curl [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-110745","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 \u0434\u043b\u044f \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f \u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0438 \u0434\u0430\u043d\u043d\u044b\u0445 \u043f\u043e \u0441\u0435\u0442\u0438 curl \u0438 \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0435\u0439\u0441\u044f \u043f\u0430\u0440\u0430\u043b\u043b\u0435\u043b\u044c\u043d\u043e \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 libcurl \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-38545), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u0431\u0443\u0444\u0435\u0440\u0430 \u0438 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/perepolnenie-bufera-v-curl-i-libcurl-proyavlyayushheesya-pri-obrashhenii-cherez-socks5-proksi\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 curl \u0438 libcurl, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0435\u0435\u0441\u044f \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0449\u0435\u043d\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 SOCKS5-\u043f\u0440\u043e\u043a\u0441\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 \u0434\u043b\u044f \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f \u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0438 \u0434\u0430\u043d\u043d\u044b\u0445 \u043f\u043e \u0441\u0435\u0442\u0438 curl \u0438 \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0435\u0439\u0441\u044f \u043f\u0430\u0440\u0430\u043b\u043b\u0435\u043b\u044c\u043d\u043e \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 libcurl \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-38545), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u0431\u0443\u0444\u0435\u0440\u0430 \u0438 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/perepolnenie-bufera-v-curl-i-libcurl-proyavlyayushheesya-pri-obrashhenii-cherez-socks5-proksi\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-10-11T19:10:17+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-10-11T19:10:17+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Desbordamiento de b\u00fafer en curl y libcurl, que se manifiesta al acceder a trav\u00e9s de un proxy SOCKS5 | ProHoster","description":"Se ha descubierto una vulnerabilidad (CVE-2023-38545) en la utilidad curl para la obtenci\u00f3n y env\u00edo de datos a trav\u00e9s de la red y en la biblioteca libcurl, que puede llevar a un desbordamiento de b\u00fafer y potencialmente a la ejecuci\u00f3n de c\u00f3digo.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/perepolnenie-bufera-v-curl-i-libcurl-proyavlyayushheesya-pri-obrashhenii-cherez-socks5-proksi","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 curl \u0438 libcurl, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0435\u0435\u0441\u044f \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0449\u0435\u043d\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 SOCKS5-\u043f\u0440\u043e\u043a\u0441\u0438 | ProHoster","og:description":"\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 \u0434\u043b\u044f \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f \u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0438 \u0434\u0430\u043d\u043d\u044b\u0445 \u043f\u043e \u0441\u0435\u0442\u0438 curl \u0438 \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0435\u0439\u0441\u044f \u043f\u0430\u0440\u0430\u043b\u043b\u0435\u043b\u044c\u043d\u043e \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 libcurl \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-38545), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u0431\u0443\u0444\u0435\u0440\u0430 \u0438 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/perepolnenie-bufera-v-curl-i-libcurl-proyavlyayushheesya-pri-obrashhenii-cherez-socks5-proksi","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-10-11T19:10:17+00:00","article:modified_time":"2023-10-11T19:10:17+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"110745","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-02-08 20:24:09","updated":"2026-02-08 20:24:09","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/110745","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=110745"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/110745\/revisions"}],"predecessor-version":[{"id":157908,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/110745\/revisions\/157908"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=110745"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=110745"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=110745"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}