CVE-2023-28319: Use After Free
A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprint before it returns an error message containing the (now freed) hash. This flaw risks inserting sensitive heap-based data into the error message that might be shown to users or otherwise get leaked and revealed.
Other sources
Accounts. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
AMD. A race condition was addressed with improved state handling.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
AppleMobileFileIntegrity. A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
— Apple
AppSandbox. A logic issue was addressed with improved restrictions.
— Apple
Credit
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-40442
- CVE-2023-34425
- CVE-2023-32364
- CVE-2023-35983
- CVE-2023-40392
- CVE-2023-34241
- CVE-2023-28319
- CVE-2023-28320
- CVE-2023-28321
- CVE-2023-28322
- CVE-2023-41990
- CVE-2023-36854
- CVE-2023-32418
- CVE-2023-32381
- CVE-2023-32433
- CVE-2023-35993
- CVE-2023-38603
- CVE-2023-38590
- CVE-2023-38598
- CVE-2023-37285
- CVE-2023-38604
- CVE-2023-38606
- CVE-2023-32441
- CVE-2023-38565
- CVE-2023-38593
- CVE-2023-38571
- CVE-2023-29491
- CVE-2023-38601
- CVE-2023-32444
- CVE-2023-2953
- CVE-2023-42829
- CVE-2023-38259
- CVE-2023-38602
- CVE-2023-42831
- CVE-2023-32443
- CVE-2023-42832
- CVE-2023-32422
- CVE-2023-32429
- CVE-2023-1801
- CVE-2023-2426
- CVE-2023-2609
- CVE-2023-2610
- CVE-2023-32416
- CVE-2023-36495
- CVE-2023-40440
- CVE-2023-38421
- CVE-2023-38258
- CVE-2023-1916
- CVE-2023-32442
- CVE-2023-38605
- CVE-2023-40439
- CVE-2023-38616
- CVE-2023-38580
- CVE-2023-36862
- CVE-2023-42828
- CVE-2023-40437
- CVE-2022-3970
- CVE-2023-28200
- CVE-2023-32734
- CVE-2023-38261
- CVE-2023-38424
- CVE-2023-38425
- CVE-2023-38410
- CVE-2023-38609
- CVE-2023-38564
- CVE-2023-32654
- CVE-2023-38608
- CVE-2023-40397
- CVE-2023-38572
- CVE-2023-38599
- CVE-2023-32445
- CVE-2023-38592
- CVE-2023-38594
- CVE-2023-38595
- CVE-2023-38600
- CVE-2023-38611
- CVE-2023-37450
- CVE-2023-42866
- CVE-2023-38597
- CVE-2023-38133
- CVE-2023-43000
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-28319.
What is the severity of CVE-2023-28319?
The severity of CVE-2023-28319 is high.
Which software is affected by CVE-2023-28319?
The software affected by CVE-2023-28319 includes Haxx Curl, Apple macOS (version 11.0 to 11.7.9), Apple macOS (version 12.0 to 12.6.8), Apple macOS (version 13.0 to 13.5), Apple macOS Big Sur, Apple macOS Monterey.
How does CVE-2023-28319 affect libcurl?
CVE-2023-28319 is a use after free vulnerability in libcurl that occurs when verifying an SSH server's public key using a SHA 256 hash.
Where can I find more information about CVE-2023-28319?
You can find more information about CVE-2023-28319 at the following references: [HackerOne report](https://hackerone.com/reports/1913733), [Seclist 1](http://seclists.org/fulldisclosure/2023/Jul/47), [Seclist 2](http://seclists.org/fulldisclosure/2023/Jul/48).