curl - SOCKS5 heap buffer overflow - CVE-2023-38545
curl.se
curl.se
I would like to note how frank and transparent Daniel is here. I really appreciate that, not only in a public venue, but also at work. I am very much for an organisational culture that enables this.
A heart-rending line. Hugs for Daniel.
This sounds like an issue in itself, even if it is intended. Is that max length of the hostname a limitation of SOCKS5?
Let's assume you're using TOR through a SOCKS5 proxy, then any tool which uses libcurl will perform a local host lookup upon a https call (or redirect) to a long hostname, like one with a dynamically assigned UUID in a subdomain.
From the advisory:
Starting in curl 8.4.0, curl no longer switches to local resolve mode if the name is too long but is instead rightfully returning an error.