{"id":110745,"date":"2023-10-11T21:10:17","date_gmt":"2023-10-11T19:10:17","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/perepolnenie-bufera-v-curl-i-libcurl-proyavlyayushheesya-pri-obrashhenii-cherez-socks5-proksi"},"modified":"2023-10-11T21:10:17","modified_gmt":"2023-10-11T19:10:17","slug":"perepolnenie-bufera-v-curl-i-libcurl-proyavlyayushheesya-pri-obrashhenii-cherez-socks5-proksi","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/perepolnenie-bufera-v-curl-i-libcurl-proyavlyayushheesya-pri-obrashhenii-cherez-socks5-proksi","title":{"rendered":"Rilascio del framework Qt 6.6","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u00c8 stata scoperta una vulnerabilit\u00e0 (CVE-2023-38545) nell'utilit\u00e0 per la ricezione e invio di dati tramite rete curl e nella parallela libreria in sviluppo libcurl, che potrebbe portare a un buffer overflow e potenzialmente all'esecuzione di codice da parte di un attaccante sul lato client quando si accede a un server HTTPS controllato dall'aggressore utilizzando curl o un'applicazione che utilizza libcurl. Il problema si manifesta solo nel caso in cui si attivi l'accesso tramite proxy SOCKS5 in curl. Non si verifica vulnerabilit\u00e0 in caso di accesso diretto senza proxy. La vulnerabilit\u00e0 \u00e8 stata corretta nella versione curl 8.4.0. Il ricercatore di sicurezza che ha individuato il bug ha ricevuto una ricompensa di $4660 nell'ambito dell'iniziativa Internet Bug Bounty su Hackerone.             <\/p>\n<p>La vulnerabilit\u00e0 \u00e8 causata da un errore nel codice di risoluzione del nome host prima di accedere al proxy SOCKS5. Con lunghezze del nome host fino a 256 caratteri, curl invia immediatamente il nome al proxy SOCKS5 per la risoluzione sul suo lato, mentre se il nome supera i 255 caratteri, passa a un risolutore locale e invia al SOCKS5 gi\u00e0 un indirizzo determinato. A causa di un errore nel codice, il flag che indica la necessit\u00e0 di una risoluzione locale, durante il processo di connessione lenta tramite SOCKS5, potrebbe essere impostato su un valore errato, portando alla registrazione di un lungo nome host in un buffer allocato per memorizzare <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/it\/lir\/ipv4\/\"   title=\"Indirizzi IP\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"717\">Indirizzi IP<\/a> o un nome che non superi 255 caratteri.      <\/p>\n<p>Il proprietario del sito a cui curl si connette tramite un proxy SOCKS5 pu\u00f2 innescare un overflow del buffer dal lato client restituendo un codice di reindirizzamento della richiesta (HTTP 30x) e impostando nell'intestazione &#171;Location:&#187; un URL con un nome host la cui dimensione \u00e8 compresa tra 16 e 64 KB (il valore di 16 KB \u00e8 determinato dalla dimensione minima necessaria per sovraccaricare il buffer allocato, mentre il valore di 65 KB \u00e8 legato alla lunghezza massima consentita del nome host nell'URL). Se nelle impostazioni di libcurl \u00e8 consentito il reindirizzamento delle richieste e il proxy SOCKS5 utilizzato \u00e8 abbastanza lento, il lungo nome host verr\u00e0 registrato in un piccolo buffer, chiaramente di dimensioni inferiori.     <\/p>\n<p>La vulnerabilit\u00e0 colpisce principalmente le applicazioni basate su libcurl e si manifesta nell'utilit\u00e0 curl solo quando viene utilizzata l'opzione &#171;&#8212;limit-rate&#187; con un valore inferiore a 65541 &#8212; in libcurl viene allocato per impostazione predefinita un buffer della dimensione di 16 KB, mentre nell'utilit\u00e0 curl &#8212; 100 KB, ma questa dimensione varia in base al valore del parametro &#171;&#8212;limit-rate&#187;.      <\/p>\n<p>Daniel Stenberg, l'autore del progetto, ha menzionato che la vulnerabilit\u00e0 \u00e8 rimasta inosservata per 1315 giorni. \u00c8 stato anche detto che il 41% delle vulnerabilit\u00e0 precedentemente scoperte in curl sarebbe probabilmente stato evitato se curl fosse stato scritto in un linguaggio che garantisce una gestione sicura della memoria, ma non sono previsti piani a breve termine per riscrivere curl in un altro linguaggio. Per aumentare la sicurezza della base di codice, si propone di ampliare gli strumenti per il testing del codice e di utilizzare in modo pi\u00f9 attivo le dipendenze scritte in linguaggi di programmazione che garantiscono una gestione sicura della memoria. Si sta anche considerando la possibilit\u00e0 di sostituire gradualmente parti di curl con varianti scritte in linguaggi sicuri, come l'HTTP backend sperimentale Hyper, implementato nel linguaggio Rust.<br \/>\n<br \/>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=59909\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 \u0434\u043b\u044f \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f \u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0438 \u0434\u0430\u043d\u043d\u044b\u0445 \u043f\u043e \u0441\u0435\u0442\u0438 curl \u0438 \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0435\u0439\u0441\u044f \u043f\u0430\u0440\u0430\u043b\u043b\u0435\u043b\u044c\u043d\u043e \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 libcurl \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-38545), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u0431\u0443\u0444\u0435\u0440\u0430 \u0438 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u0433\u043e \u043d\u0430 \u0441\u0442\u043e\u0440\u043e\u043d\u0435 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0449\u0435\u043d\u0438\u0438 \u043f\u0440\u0438 \u043f\u043e\u043c\u043e\u0449\u0438 \u0443\u0442\u0438\u043b\u0438\u0442\u044b curl \u0438\u043b\u0438 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0449\u0435\u0433\u043e libcurl, \u043a HTTPS-\u0441\u0435\u0440\u0432\u0435\u0440\u0443, \u043f\u043e\u0434\u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044c\u043d\u043e\u043c\u0443 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0443. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0442\u043e\u043b\u044c\u043a\u043e \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0432 curl [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-110745","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 \u0434\u043b\u044f \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f \u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0438 \u0434\u0430\u043d\u043d\u044b\u0445 \u043f\u043e \u0441\u0435\u0442\u0438 curl \u0438 \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0435\u0439\u0441\u044f \u043f\u0430\u0440\u0430\u043b\u043b\u0435\u043b\u044c\u043d\u043e \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 libcurl \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-38545), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u0431\u0443\u0444\u0435\u0440\u0430 \u0438 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/perepolnenie-bufera-v-curl-i-libcurl-proyavlyayushheesya-pri-obrashhenii-cherez-socks5-proksi\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 curl \u0438 libcurl, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0435\u0435\u0441\u044f \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0449\u0435\u043d\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 SOCKS5-\u043f\u0440\u043e\u043a\u0441\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 \u0434\u043b\u044f \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f \u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0438 \u0434\u0430\u043d\u043d\u044b\u0445 \u043f\u043e \u0441\u0435\u0442\u0438 curl \u0438 \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0435\u0439\u0441\u044f \u043f\u0430\u0440\u0430\u043b\u043b\u0435\u043b\u044c\u043d\u043e \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 libcurl \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-38545), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u0431\u0443\u0444\u0435\u0440\u0430 \u0438 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/perepolnenie-bufera-v-curl-i-libcurl-proyavlyayushheesya-pri-obrashhenii-cherez-socks5-proksi\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-10-11T19:10:17+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-10-11T19:10:17+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Overflow del buffer in curl e libcurl, che si manifesta durante l'accesso tramite un proxy SOCKS5 | ProHoster","description":"Nel utility di ricezione e invio dati tramite rete curl e nella libreria in fase di sviluppo libcurl \u00e8 stata identificata una vulnerabilit\u00e0 (CVE-2023-38545), che potrebbe portare a un overflow del buffer e potenzialmente all'esecuzione.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/perepolnenie-bufera-v-curl-i-libcurl-proyavlyayushheesya-pri-obrashhenii-cherez-socks5-proksi","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435 \u0431\u0443\u0444\u0435\u0440\u0430 \u0432 curl \u0438 libcurl, \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u044e\u0449\u0435\u0435\u0441\u044f \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0449\u0435\u043d\u0438\u0438 \u0447\u0435\u0440\u0435\u0437 SOCKS5-\u043f\u0440\u043e\u043a\u0441\u0438 | ProHoster","og:description":"\u0412 \u0443\u0442\u0438\u043b\u0438\u0442\u0435 \u0434\u043b\u044f \u043f\u043e\u043b\u0443\u0447\u0435\u043d\u0438\u044f \u0438 \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0438 \u0434\u0430\u043d\u043d\u044b\u0445 \u043f\u043e \u0441\u0435\u0442\u0438 curl \u0438 \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u044e\u0449\u0435\u0439\u0441\u044f \u043f\u0430\u0440\u0430\u043b\u043b\u0435\u043b\u044c\u043d\u043e \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0435 libcurl \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2023-38545), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u0431\u0443\u0444\u0435\u0440\u0430 \u0438 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/perepolnenie-bufera-v-curl-i-libcurl-proyavlyayushheesya-pri-obrashhenii-cherez-socks5-proksi","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-10-11T19:10:17+00:00","article:modified_time":"2023-10-11T19:10:17+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"110745","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-02-08 20:24:09","updated":"2026-02-08 20:24:09","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/110745","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=110745"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/110745\/revisions"}],"predecessor-version":[{"id":157908,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/110745\/revisions\/157908"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=110745"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=110745"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=110745"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}