First published: Wed Jul 19 2023(Updated: )
Hiroki Kurosawa discovered that curl incorrectly handled validating certain certificate wildcards. A remote attacker could possibly use this issue to spoof certain website certificates using IDN hosts. (CVE-2023-28321) Hiroki Kurosawa discovered that curl incorrectly handled callbacks when certain options are set by applications. This could cause applications using curl to misbehave, resulting in information disclosure, or a denial of service. (CVE-2023-28322) It was discovered that curl incorrectly handled saving cookies to files. A local attacker could possibly use this issue to create or overwrite files. This issue only affected Ubuntu 22.10, and Ubuntu 23.04. (CVE-2023-32001)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libcurl3-gnutls | <7.88.1-8ubuntu2.1 | 7.88.1-8ubuntu2.1 |
=23.04 | ||
All of | ||
ubuntu/libcurl3-nss | <7.88.1-8ubuntu2.1 | 7.88.1-8ubuntu2.1 |
=23.04 | ||
All of | ||
ubuntu/libcurl4 | <7.88.1-8ubuntu2.1 | 7.88.1-8ubuntu2.1 |
=23.04 | ||
All of | ||
ubuntu/curl | <7.88.1-8ubuntu2.1 | 7.88.1-8ubuntu2.1 |
=23.04 | ||
All of | ||
ubuntu/libcurl3-gnutls | <7.85.0-1ubuntu0.6 | 7.85.0-1ubuntu0.6 |
=22.10 | ||
All of | ||
ubuntu/libcurl3-nss | <7.85.0-1ubuntu0.6 | 7.85.0-1ubuntu0.6 |
=22.10 | ||
All of | ||
ubuntu/libcurl4 | <7.85.0-1ubuntu0.6 | 7.85.0-1ubuntu0.6 |
=22.10 | ||
All of | ||
ubuntu/curl | <7.85.0-1ubuntu0.6 | 7.85.0-1ubuntu0.6 |
=22.10 | ||
All of | ||
ubuntu/libcurl3-gnutls | <7.81.0-1ubuntu1.11 | 7.81.0-1ubuntu1.11 |
=22.04 | ||
All of | ||
ubuntu/libcurl3-nss | <7.81.0-1ubuntu1.11 | 7.81.0-1ubuntu1.11 |
=22.04 | ||
All of | ||
ubuntu/libcurl4 | <7.81.0-1ubuntu1.11 | 7.81.0-1ubuntu1.11 |
=22.04 | ||
All of | ||
ubuntu/curl | <7.81.0-1ubuntu1.11 | 7.81.0-1ubuntu1.11 |
=22.04 | ||
All of | ||
ubuntu/libcurl3-gnutls | <7.68.0-1ubuntu2.19 | 7.68.0-1ubuntu2.19 |
=20.04 | ||
All of | ||
ubuntu/libcurl3-nss | <7.68.0-1ubuntu2.19 | 7.68.0-1ubuntu2.19 |
=20.04 | ||
All of | ||
ubuntu/libcurl4 | <7.68.0-1ubuntu2.19 | 7.68.0-1ubuntu2.19 |
=20.04 | ||
All of | ||
ubuntu/curl | <7.68.0-1ubuntu2.19 | 7.68.0-1ubuntu2.19 |
=20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The vulnerability ID for this advisory is USN-6237-1.
The severity of the vulnerability is not specified in the provided information.
The software versions affected by the vulnerability are libcurl3-gnutls, libcurl3-nss, libcurl4, and curl.
This vulnerability can be exploited by a remote attacker to possibly spoof certain website certificates using IDN hosts.
To fix the vulnerability, update the affected software to the recommended remedy version specified for each package.