USN-6429-2: curl vulnerability
Published Oct 11, 2023
·Updated
USN-6429-1 fixed a vulnerability in curl. This update provides the corresponding update for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. Original advisory details: It was discovered that curl incorrectly handled cookies when an application duplicated certain handles. A local attacker could possibly create a cookie file and inject arbitrary cookies into subsequent connections. (CVE-2023-38546)
Affected Software
24 affected componentsFixes available
All of the following
ubuntu/curl<7.58.0-2ubuntu3.24+esm2
7.58.0-2ubuntu3.24+esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libcurl3-gnutls<7.58.0-2ubuntu3.24+esm2
7.58.0-2ubuntu3.24+esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libcurl3-nss<7.58.0-2ubuntu3.24+esm2
7.58.0-2ubuntu3.24+esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libcurl4<7.58.0-2ubuntu3.24+esm2
7.58.0-2ubuntu3.24+esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/curl<7.47.0-1ubuntu2.19+esm10
7.47.0-1ubuntu2.19+esm10
Ubuntu Ubuntu=16.04
All of the following
ubuntu/libcurl3<7.47.0-1ubuntu2.19+esm10
7.47.0-1ubuntu2.19+esm10
Ubuntu Ubuntu=16.04
All of the following
ubuntu/libcurl3-gnutls<7.47.0-1ubuntu2.19+esm10
7.47.0-1ubuntu2.19+esm10
Ubuntu Ubuntu=16.04
All of the following
ubuntu/libcurl3-nss<7.47.0-1ubuntu2.19+esm10
7.47.0-1ubuntu2.19+esm10
Ubuntu Ubuntu=16.04
All of the following
ubuntu/curl<7.35.0-1ubuntu2.20+esm17
7.35.0-1ubuntu2.20+esm17
Ubuntu Ubuntu=14.04
All of the following
ubuntu/libcurl3<7.35.0-1ubuntu2.20+esm17
7.35.0-1ubuntu2.20+esm17
Ubuntu Ubuntu=14.04
All of the following
ubuntu/libcurl3-gnutls<7.35.0-1ubuntu2.20+esm17
7.35.0-1ubuntu2.20+esm17
Ubuntu Ubuntu=14.04
All of the following
ubuntu/libcurl3-nss<7.35.0-1ubuntu2.20+esm17
7.35.0-1ubuntu2.20+esm17
Ubuntu Ubuntu=14.04
Event History
Oct 11, 2023
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is USN-6429-2.
2
What is the severity of USN-6429-2?
The severity of USN-6429-2 is not specified.
3
What software versions are affected by USN-6429-2?
USN-6429-2 affects Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.
4
How does USN-6429-2 affect curl?
USN-6429-2 fixes a vulnerability in curl.
5
Where can I find more information about USN-6429-2?
You can find more information about USN-6429-2 on the Ubuntu security website.