CVE-2023-38546: Curl and libcurl CVE-2023-38545 and CVE-2023-38546 vulnerabilities
Published Oct 3, 2023
·Updated
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Credit
CVE-2023-38545, CVE-2023-38039, CVE-2023-38546, Mickey Jin@@patch1t, an anonymous researcher, Marc Newlin(SkySafe), Koh M. Nakagawa@@tsunek0h, Yann GASCUEL(Alter Solutions), Anthony Cruz Tyrant Corp@@App, Wojciech Regula(SecuRing), Zhenjiang Zhao(Pangu Team), Qianxin, Junsung Lee, Meysam Firouzi@@R00tkitSMM, Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Pan ZhenPeng@@Peterpan0927(STAR Labs SG Pte), Eloi Benoist-Vanderbeken@@elvanderb(Synacktiv), CVE-2023-42893, CVE-2023-3618, CVE-2020-19185, CVE-2020-19186, CVE-2020-19187, CVE-2020-19188, CVE-2020-19189, CVE-2020-19190, Ron Masas(BreakPoint), Csaba Fitzl@@theevilbit(OffSec), Csaba Fitzl@@theevilbit(Offensive Security), Arsenii Kostromin (0x3c3e), Mattie Behrens, Joshua Jewett@@JoshJewett33, Zhongquan Li@@Guluisacat, Zhongquan Li@@Guluisacat(Dawn Security Lab of JingDong), CVE-2023-5344, Pwn2car, Zoom Offensive Security Team, Nan Wang@@eternalsakura13(360 Vulnerability Research Institute), rushikesh nandedkar, SungKwon Lee (Demon.Team), Noah Roskin-Frazee, Pr, Ivan Fratric(Google Project Zero), (Trend Micro Zero Day Initiative), Don Clarke, Kirin@@Pwnrin, CVE-2023-42915, Apple
Affected Software
25 affected componentsFixes available
ubuntu/curl<7.58.0-2ubuntu3.24+
7.58.0-2ubuntu3.24+
ubuntu/curl<7.68.0-1ubuntu2.20
7.68.0-1ubuntu2.20
ubuntu/curl<7.81.0-1ubuntu1.14
7.81.0-1ubuntu1.14
ubuntu/curl<7.88.1-8ubuntu2.3
7.88.1-8ubuntu2.3
ubuntu/curl<8.2.1-1ubuntu3.1
8.2.1-1ubuntu3.1
ubuntu/curl<8.2.1-1ubuntu3.1
8.2.1-1ubuntu3.1
ubuntu/curl<7.35.0-1ubuntu2.20+
7.35.0-1ubuntu2.20+
ubuntu/curl<7.47.0-1ubuntu2.19+
7.47.0-1ubuntu2.19+
debian/curl
7.74.0-1.3+deb11u127.74.0-1.3+deb11u117.88.1-10+deb12u67.88.1-10+deb12u58.8.0-48.9.1-1
Apple macOS Sonoma<14.2
14.2
haxx libcurl>=7.9.1<8.4.0
Apple macOS Monterey<12.7.3
12.7.3
Fortinet FortiExtender>=7.4.0<=7.4.1
Fortinet FortiExtender>=7.2.0<=7.2.3
Fortinet FortiOS (only FGT_VM64)>=7.4.0<=7.4.1
Fortinet FortiOS (only FGT_VM64)>=7.2.0<=7.2.6
Fortinet FortiOS (only FGT_VM64)>=7.0.1<=7.0.13
Fortinet FortiProxy (only FortiProxy_VM64)>=7.4.0<=7.4.1
Fortinet FortiProxy (only FortiProxy_VM64)>=7.2.0<=7.2.7
Fortinet FortiProxy (only FortiProxy_VM64)>=7.0
Apple macOS Ventura<13.6.4
13.6.4
Apple iOS<16.7.5
16.7.5
Apple iPadOS<16.7.5
16.7.5
redhat/curl<8.4.0
8.4.0
IBM QRadar Network Packet Capture<=7.5.0 - 7.5.0 Update Package 7
Remediation
Patch Available
Patch Available
Event History
Oct 3, 2023
Data Sourced
via Red Hat·02:09 PM
DescriptionSeverityAffected Software
Oct 11, 2023
CVE Published
via Ubuntu·12:00 AM
Oct 18, 2023
CVE Published
via MITRE·03:51 AM
Data Sourced
via MITRE·03:51 AM
Description
Data Sourced
04:15 AM
Description
Data Sourced
via NVD·04:15 AM
RemedyDescriptionSeverityAffected Software
Nov 14, 2023
Advisory Published
via FortiGuard·12:00 AM
Dec 11, 2023
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
Description
Feb 1, 2024
Data Sourced
via Launchpad·12:29 AM
Description
Jul 23, 2024
Data Sourced
via IBM·12:00 AM
DescriptionSeverityAffected Software
Oct 12, 2024
Advisory Published
via FortiGuard·12:00 AM
Frequently Asked Questions
1
What is CVE-2023-38546?
CVE-2023-38546 is a vulnerability in curl that allows cookie injection with none file.
2
How does CVE-2023-38546 affect Ubuntu?
CVE-2023-38546 affects Ubuntu versions 7.68.0-1ubuntu2.20, 7.81.0-1ubuntu1.14, and 7.88.1-8ubuntu2.3.
3
How does CVE-2023-38546 affect Debian?
CVE-2023-38546 affects Debian versions 7.64.0-4+deb10u7, 7.74.0-1.3+deb11u10, 7.88.1-10+deb12u4, and 8.3.0-3.
4
Where can I find more information about CVE-2023-38546?
You can find more information about CVE-2023-38546 on the MITRE CVE website, the curl documentation, and the Ubuntu security notices page.
5
How can I fix CVE-2023-38546?
To fix CVE-2023-38546, update curl to the recommended versions provided by the respective Linux distributions.