First published: Wed Jul 19 2023(Updated: )
** REJECT ** We issued this CVE pre-maturely, as we have subsequently realized that this issue points out a problem that there really is no safe measures around or protections for.
Credit: support@hackerone.com support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Haxx Libcurl | >=7.84.0<=8.1.2 | |
Debian Debian Linux | =12.0 | |
Fedoraproject Fedora | =37 | |
IBM IBM® Engineering Requirements Management DOORS | <=9.7.2.7 | |
IBM IBM® Engineering Requirements Management DOORS Web Access | <=9.7.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-32001 is a vulnerability in libcurl that allows an attacker to create or overwrite protected files through a TOCTOU race condition.
CVE-2023-32001 has a severity level of medium.
The affected software includes Haxx Libcurl (versions 7.84.0 to 8.1.2), Debian Debian Linux 12.0, and Fedoraproject Fedora 37.
An attacker can exploit CVE-2023-32001 by tricking the victim into creating or overwriting protected files.
You can find more information about CVE-2023-32001 at the following references: - [HackerOne Report](https://hackerone.com/reports/2039870) - [Debian Security Advisory](https://www.debian.org/security/2023/dsa-5460) - [Fedora Project Mailing List](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BGJ7POX4ATGERTSBFJPW2EQH4Z65PSZJ/)