CVE-2023-38546: Curl and libcurl CVE-2023-38545 and CVE-2023-38546 vulnerabilities
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Other sources
Accessibility. This issue was addressed with improved state management.
— Apple
Accounts. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
AppleEvents. This issue was addressed with improved redaction of sensitive information.
— Apple
AppleGraphicsControl. Multiple memory corruption issues were addressed with improved input validation.
— Apple
AppleVA. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/curlto a version that resolves this vulnerability.Fixed in 7.58.0-2ubuntu3.24+ - Upgrade
Upgrade
ubuntu/curlto a version that resolves this vulnerability.Fixed in 7.68.0-1ubuntu2.20 - Upgrade
Upgrade
ubuntu/curlto a version that resolves this vulnerability.Fixed in 7.81.0-1ubuntu1.14 - Upgrade
Upgrade
ubuntu/curlto a version that resolves this vulnerability.Fixed in 7.88.1-8ubuntu2.3 - Upgrade
Upgrade
ubuntu/curlto a version that resolves this vulnerability.Fixed in 8.2.1-1ubuntu3.1 - Upgrade
Upgrade
ubuntu/curlto a version that resolves this vulnerability.Fixed in 7.35.0-1ubuntu2.20+ - Upgrade
Upgrade
ubuntu/curlto a version that resolves this vulnerability.Fixed in 7.47.0-1ubuntu2.19+ - Upgrade
Upgrade
debian/curlto a version that resolves this vulnerability.Fixed in 7.74.0-1.3+deb11u12Fixed in 7.74.0-1.3+deb11u11Fixed in 7.88.1-10+deb12u6Fixed in 7.88.1-10+deb12u5Fixed in 8.8.0-4Fixed in 8.9.1-1 - Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 14.2 - Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 12.7.3 - Upgrade
Upgrade
macOS Venturato a version that resolves this vulnerability.Fixed in 13.6.4 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 16.7.5 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 16.7.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.2 - Upgrade
Upgrade
redhat/curlto a version that resolves this vulnerability.Fixed in 8.4.0 - Upgrade
Upgrade
curlto a version that resolves this vulnerability.Fixed in 8.4.0 - Upgrade
Upgrade
libcurlto a version that resolves this vulnerability.Fixed in 8.4.0 - Compensating control
If you use libcurl APIs like curl_easy_duphandle, avoid duplicating easy handles while cookies are enabled unless the source handle has an explicit cookies source set (to prevent unintended loading from a file named `none` when the cloned handle does not explicitly set a source to load cookies from).
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-42874
- CVE-2023-42937
- CVE-2023-42919
- CVE-2023-42894
- CVE-2023-42901
- CVE-2023-42902
- CVE-2023-42912
- CVE-2023-42903
- CVE-2023-42904
- CVE-2023-42905
- CVE-2023-42906
- CVE-2023-42907
- CVE-2023-42908
- CVE-2023-42909
- CVE-2023-42910
- CVE-2023-42911
- CVE-2023-42926
- CVE-2023-42882
- CVE-2023-42881
- CVE-2023-42924
- CVE-2023-42896
- CVE-2023-42884
- CVE-2023-45866
- CVE-2023-42900
- CVE-2023-42886
- CVE-2023-38545
- CVE-2023-38039
- CVE-2023-38546
- CVE-2023-42931
- CVE-2023-42892
- CVE-2023-42922
- CVE-2023-42898
- CVE-2023-42899
- CVE-2023-42888
- CVE-2023-42891
- CVE-2023-42974
- CVE-2023-42914
- CVE-2023-42893
- CVE-2023-3618
- CVE-2020-19185
- CVE-2020-19186
- CVE-2020-19187
- CVE-2020-19188
- CVE-2020-19189
- CVE-2020-19190
- CVE-2023-42887
- CVE-2023-42936
- CVE-2023-40390
- CVE-2023-42842
- CVE-2023-42930
- CVE-2023-42913
- CVE-2023-42932
- CVE-2023-42947
- CVE-2023-40389
- CVE-2023-5344
- CVE-2023-42890
- CVE-2023-42883
- CVE-2023-42950
- CVE-2023-42956
- CVE-2024-23212
- CVE-2024-23207
- CVE-2024-27791
- CVE-2024-23222
- CVE-2023-40528
- CVE-2024-23224
- CVE-2023-42935
- CVE-2023-42915
- CVE-2024-23211
- CVE-2024-23213
- CVE-2024-23214
- CVE-2024-23206
- CVE-2023-43010
Frequently Asked Questions
What is CVE-2023-38546?
CVE-2023-38546 is a vulnerability in curl that allows cookie injection with none file.
How does CVE-2023-38546 affect Ubuntu?
CVE-2023-38546 affects Ubuntu versions 7.68.0-1ubuntu2.20, 7.81.0-1ubuntu1.14, and 7.88.1-8ubuntu2.3.
How does CVE-2023-38546 affect Debian?
CVE-2023-38546 affects Debian versions 7.64.0-4+deb10u7, 7.74.0-1.3+deb11u10, 7.88.1-10+deb12u4, and 8.3.0-3.
Where can I find more information about CVE-2023-38546?
You can find more information about CVE-2023-38546 on the MITRE CVE website, the curl documentation, and the Ubuntu security notices page.
How can I fix CVE-2023-38546?
To fix CVE-2023-38546, update curl to the recommended versions provided by the respective Linux distributions.