USN-6237-1: curl vulnerabilities
Hiroki Kurosawa discovered that curl incorrectly handled validating certain certificate wildcards. A remote attacker could possibly use this issue to spoof certain website certificates using IDN hosts. (CVE-2023-28321) Hiroki Kurosawa discovered that curl incorrectly handled callbacks when certain options are set by applications. This could cause applications using curl to misbehave, resulting in information disclosure, or a denial of service. (CVE-2023-28322) It was discovered that curl incorrectly handled saving cookies to files. A local attacker could possibly use this issue to create or overwrite files. This issue only affected Ubuntu 22.10, and Ubuntu 23.04. (CVE-2023-32001)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this advisory?
The vulnerability ID for this advisory is USN-6237-1.
What is the severity of the vulnerability?
The severity of the vulnerability is not specified in the provided information.
What software versions are affected by the vulnerability?
The software versions affected by the vulnerability are libcurl3-gnutls, libcurl3-nss, libcurl4, and curl.
How can this vulnerability be exploited?
This vulnerability can be exploited by a remote attacker to possibly spoof certain website certificates using IDN hosts.
How can I fix the vulnerability?
To fix the vulnerability, update the affected software to the recommended remedy version specified for each package.