USN-6237-3: curl vulnerabilities
USN-6237-1 fixed several vulnerabilities in curl. This update provides the corresponding updates for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. Original advisory details: Hiroki Kurosawa discovered that curl incorrectly handled validating certain certificate wildcards. A remote attacker could possibly use this issue to spoof certain website certificates using IDN hosts. (CVE-2023-28321) Hiroki Kurosawa discovered that curl incorrectly handled callbacks when certain options are set by applications. This could cause applications using curl to misbehave, resulting in information disclosure, or a denial of service. (CVE-2023-28322) It was discovered that curl incorrectly handled saving cookies to files. A local attacker could possibly use this issue to create or overwrite files. This issue only affected Ubuntu 22.10, and Ubuntu 23.04. (CVE-2023-32001)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this advisory?
The vulnerability ID for this advisory is USN-6237-3.
What is the affected software for this vulnerability?
The affected software for this vulnerability is curl, libcurl3-gnutls, libcurl3-nss, and libcurl4.
What is the severity of this vulnerability?
The severity of this vulnerability is not mentioned in the advisory.
How can I fix this vulnerability?
To fix this vulnerability, you need to update curl and its related packages to the specified versions.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability in the references section of the advisory.